Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - djprmf

Pages: [1] 2 3 ... 6
1
Updates / Re: cwp service failed
« on: July 28, 2026, 11:19:43 AM »
https://forum.centos-webpanel.com/updates/alma-9-1-3-update/msg53773/?topicseen#msg53773

Let's discuss the issues in a single post; otherwise, a bunch of topics will get opened, and it will just create chaos again.

This appears to be the main topic, and was first, so makes sense consider it the "main" topic about the issue.
The one stated is related, but have other issues. ;)

2
Updates / Re: cwp service failed
« on: July 28, 2026, 10:33:05 AM »
How to fix it

Enter by SSH and run:
/usr/local/cwpsrv/htdocs/resources/scripts/generate_hostname_ssl

This could allow to enter the panel - with a SSL error.
After the login, go to "Server Settings" > "Change Hostname", and just click the button "Change Hostname".
This will recreate the SSL and allow to enter.

If the domain of the server have HSTS, enter in the panel by the IP of the server:
https://SERVERIP:2031/
Ignore the SSL error and continue with the same steps as before.

Also, after everything goes back to normal, run the CWP updated by SSH.
sh /scripts/update_cwp

Appears that there is a "1.3" new version that seems to be somehow big.

3
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« on: July 06, 2026, 05:42:23 PM »
Yes, every software can and will have vulnerabilities...

... but most of them notify the users about it and NOT silently patch the issue.
ALL the software that you stated, every single one of them... there WAS a statement from the developers about the issue.

Do you have ANY security fix statement from CWP dev team? to ANY vulnerability?

4
@cyberspace

Every single panel that i know provide a list of ALL the fixes made...
And even more, when there is a critical issue, most of the provide a full detail information of what is happening... not silence.

Do you need a example? Just look to the recent cPanel fiasco - the patch was not even lauched and there was a security notice in the blog providing FULL details about the issue... or just something that provide info to the users.
That IS common practice.

And answering your question: yes, i think me and anyone with any tech knowledge WANT to see a full changelog of everything that changed. In fact, here in Europe, is LAW... so...

5
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« on: July 06, 2026, 05:29:57 PM »
@cyberspace

Please, don't try to deflect the issue - and even worst, try to deflect that issue to the users.

The vulnerability, before being patched, was active and was capable of being exploited... In true, that doesn't mean that THIS particular issue in this topic WAS because of this, but is just too much coincidence.
Lets just remember that there WAS another critical security issue in CWP, that WAS exploited, with multiple servers hacked... and we still don't have ANY info from the dev team about what happend... not even "sorry".

Even if is currently patched, that doesn't mean that some servers didn't get exploited BEFORE the patch was issued...

6
@cyberspace

You completly miss the point, don't you?

8
As always... there is a new critical security vulnerability in CWP:
https://www.cve.org/CVERecord?id=CVE-2026-57517
https://ccb.belgium.be/advisories/warning-cve-2026-57517-cvss-98-blind-sql-injection-control-web-panel-lets

No info about it.
Along side, there are multiple updates done in the past few days with critical changes - and bugs - and NO ONE says anything about this.

There is a bug that wipe all the SSH keys on the servers - no dev says anything.
There is a CVE for a critical security issue - was silently patch and no one says nothing.
There is a new script that do whatever it does in any server, looking for a mysterious SSH key... and no info is provided about what is or what happend...

And of course: the forums are always down so no one can report anything. And the "excuse" is that is under a DDoS attack - of course, that is a excuse, since there is NO attack, and is a misconfigured server.

Along that:
Multiple updates with no changelog. Nothing. We only see numbers increase... and nothing being said about what is new, what changed or what was fixed. Silence.
Multiple bugs, introduced by the multiple updates without changelog, that have no fix.


And still, there are the same people here in the forum that defend everything, and say that the issue "is not CWP, is toxic user X or Y", or "everything is fine"...
Clearly, this is not fine. CWP have issues, for months. For months there have been reports and users telling that they just want to know what is happening...

We just want to hear: What is going on??

And still: no dev answers. Just the same users - most of them in a bubble that "everything is fine" - and providing danger info to any user that still is around here looking to know what is going on...

9
Updates / Re: Did 0.9.8.1239 remove extra DB users?
« on: July 03, 2026, 10:21:55 AM »
And here we have the issues that happen when we have no changelog of new updates... We never know what have changed.

10
Information / Re: Changelogs updated
« on: March 17, 2026, 02:02:03 PM »
Some one has finally took the time to update the changlogs

Looks like giving feedback about improvements to be made to help CWP to grow, actually helps. Instead of closed mind and toxic behaviour that everything is "critics". Who knew....

Good to see, and hope to continue the trend of constant changelog updates.

11
Updates / Re: Roundcube vulnerability
« on: March 08, 2026, 04:36:08 PM »
Yes... now, instead of reply with toxic, can you back to the original question?

Note that is YOU that are being offtopic with toxic answers, not me. Don't say BS in something that anyone can read, is a little dumb.
Otherwise, kindle provide any proof in how did i write any misinformation. If you cannot, YOU are being the toxic here, not me, so shut up.

Now, back to where all this started: a message from me thanking the users for the script. Thats it... everything after that was ignited from toxic replies... and ANYONE can read that so don't even answer please.

12
PHP / Re: When will PHP 8.4 be released in CWP?
« on: March 08, 2026, 04:32:51 PM »
@cHAp
This topic was last replied +4 months, and you literally didn't answer here after that time. The discussion taking place after that was ignited from the toxicity made from some users... nothing to do with you..
Your last reply was August 06, 2025...

But, with that said: You decided reply to a dead topic again, so don't blame others in reignite the issue. You didn't have to reply, no one was said anything about you...

What doesn't make sense is the question from @cyberspace, since that have nothing to do with your question nor your last reply...
What is your issue exactly?


13
PHP / Re: When will PHP 8.4 be released in CWP?
« on: March 08, 2026, 09:33:04 AM »
Hello,

When can we expect PHP 8.4 to be available in CWP? I couldn't find an answer in the forum itself!

Best regards,
cHAp

That is NOT your screenname cpanel envangelist, unless you are opening multiple profiles just to troll...

You know so much, answer that users question, and not with another troll post...

Hello,

I have nothing to do with the user DJPRMF! I was serious about my question when I created the thread. I also contacted support via ticket. On August 6, 2025, they said: "It will be available in a future version."

Unfortunately, there has been no update to this day.

I distance myself from the user DJPRMF. I don't use cPanel. I only use CWP. In case anyone suspects I am DJPRMF, if I've translated that correctly into German...

Best regards,
cHAp

cHAp, your answer have been replied... and that is just what you get here just because point out something "bad" about CWP. Ignore the envangelists and the drama, and follow all the replies that have been provided. :)

14
Updates / Re: Roundcube vulnerability
« on: March 08, 2026, 09:30:39 AM »
If you aren't satisfied with CWP then I don't understand why you are here.
Don't waste your time. I wish you luck finding another modern all-in-one control panel that meets your requirements.

And i did, as many others. But that doesn't mean i don't follow the project...

15
Updates / Re: Roundcube vulnerability
« on: March 06, 2026, 12:37:49 AM »
Excessive hyperbole. There's nothing wrong with LTS versions.

And i didnt say that there is...
LTS is great... to support old tech. So is a bandage, not a fix.

Pages: [1] 2 3 ... 6