This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Pages: [1]
1
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: November 25, 2025, 11:08:20 AM »CWP 0.9.8.1218 has this original bug fixed for a long time with the File Manager.
What you posted in a WordPress path.
Simple fix, don't use WordPress, or use a security plugin.
Also secure you PHP.ini under disable_functions =
If your not sure how to secure a server or clean one after an attack, you might want to think about hiring a sys admin.
Done with disable_functions = and comodo. Thank you for replay.
disable_functions =
2
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: November 23, 2025, 02:48:54 PM »My wordpress wibsites also infeted. And other websites non worpress also. Replaced index.php, added licelic.c" backup.c defauit.php. I found admin accounts in database WP-user wpadmin@volovmart.ru. I dont know how its happened. But i think it is Panel hacked because it is not effect only WordPress CMS. Im using CWP pro.Hello,
We're encountering the same situation on one of our servers.
While we're actively performing cleanup operations, the critical question remains: Has this vulnerability truly been resolved by the "silent patch"?
Do you have any informations about when end what version of the patch/update ?
Best regards,I have the same problem. My VPS are infected.
Im using CWPpro version: 0.9.8.1218 and Rocky Linux release 9.5
After the intrusion i have problems with SEO, google results display titles from other sources.
My websites traffic has plummeted in the last few days because of this change. When I type site:mysomain.tld into Google, I see that the results point to my websites, but the text is different.
Does anyone else have this problem? Do you know how to fix it? How did you manage to change it? I've already submitted sitemaps to Google Search Console, but I'm not sure if it will work.
First thing to do is renaming /usr/local/cwpsrv/var/services/user_files/modules/filemanager.php as /usr/local/cwpsrv/var/services/user_files/modules/filemanager.php.disabled
Then follow the messages sent by @pedromidiasf and me at page 5 to page 7. You will see the names of the malicious files dropped by attackers.
What exploiters are capable of is equal to filemanager at the start and this might not seem worrying. But then they take full advantage of PHP so if they want to remove whole of your files, they can and they can redirect your visitors to other websites.
If I was the one whos using this exploit I could convert this to a DDoS tool by redirecting every visitor to the website that I want to cause DoS. So, there is no limit, they can do anything they want and every IT admin should take this seriously.
Hi friend im still fighting for fix it. Disabling filemanager temporarily solution. My sites traffic growing. I deleted all infected files. Enabled Mo sec rules. Scanned all wordpress websites with wordfence. But still upload available over POST i see in logi every 2 days/ My index files on my webpages replacing to hacker files. I found folders with permission 777 in my server. Sadly CWP havent reinstall or uninstall solution for such as case for fix hacked files.
3
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: November 23, 2025, 02:05:45 PM »
Even CWPpro version: 0.9.8.1218 version still 3/Nov/2025:13:12:40 +0400] "POST /uploads/leads/1/index.php? working for hack. I enable all security tools. But still not luck.
5
Other / Panel hacked and all my site infected
« on: November 19, 2025, 09:29:27 AM »
My CWP panel hacked 3-4 months ago and i clear all hacker files. All pages indexed and url still active. when enter https://domain.com/?o=89095421 yes link going to the website home page but in google index i have 1000 indexed pages like this https://domain.com/?o=89095421 Reinstalled wordpress websites. Even i delete domain with account from server for check links with CWP default page but still url working. That mean website databases clean but something still on CWP panel. when i check the usrl https://domain.com/?o=89095421 in google inspection url still a live. I dont want resintall CWP and lot of accounts. Mybe someone have information and solution regarding my case.
6
Mod_Security / Re: OWASP Latest
« on: October 22, 2025, 03:15:43 PM »
They still have access after cleaning password changing. I got 3 files licelic.c robots.txt and index.php changed again. and of course website not working. Every Security application for protect enabled on panel. Scan showing 0 infections.
7
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: October 17, 2025, 10:14:41 AM »
My wordpress wibsites also infeted. And other websites non worpress also. Replaced index.php, added licelic.c" backup.c defauit.php. I found admin accounts in database WP-user wpadmin@volovmart.ru. I dont know how its happened. But i think it is Panel hacked because it is not effect only WordPress CMS. Im using CWP pro.
8
Suggestions / Re: Backup to Amazon S3
« on: June 30, 2025, 02:16:05 AM »
Im looking that solution also. Suggested in 2017 no 2025 still not included.
Pages: [1]

