Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - djprmf

Pages: 1 2 [3] 4 5 6
31
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 24, 2025, 05:05:23 PM »
Dude... You are asking me to answer a question that I make...

Stop being a kid and try increase your ego please with nonsense attacks... You are asking me to answer my own question? And asking for focus when are YOU that are reply with nonsense..

So yes kid, FOCUS!

32
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 24, 2025, 03:57:28 PM »
So go ahead and answer the question cpanel envangelist with a solution...

ALL you do is post BS troll posts...

So FOCUS...

You are the one asking me to answer my own question... And again, not answering.... Dude....

33
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 24, 2025, 08:38:52 AM »
Ok, and now... anyone can answer the topic?

Using insults and nonsense doesn't answer a single question point made here. If you cannot answer anything just don't reply. Im here answering the questions of the TOPIC - both of you are coming here to insult and talk BS... and i am the "bad guy"? :)

is simple: prove me wrong. Talk to the topic, answer. And don't hide under a "cpanel envagelist" - really, is a little cringe that the only thing to answer to things is that.... that is called deflect the point, not answering.

And @Starburst, you specific, continue to attack as "cpanel envangelist"... and now i ask you: you have a hosting company, and a datacenter with multiple servers/clients. But you only provide CWP to them. Lets say that CWP cease development tomorrow.
What do you do?
You company probalby will enter in panic mode. So... why provide multiple control panels is a "bad thing"? I provide cPanel, as i provide CWP, Hestia, and many more. That is not a bad thing, is called diversification. If anything happens to one panel, i can adjust to other. That is not called "cpanel eenvagelist", is called think about the needs of the clients and the future.
yes, because i have clients asking specificly for cPanel, as i have to Plesk, CWP and others... Is that dumb to provide a panel that the clients want? If you don't, that is on you, but is not how i do business.

And cPanel does A LOT of things bad. Do you think that i consider cPanel perfect? From a company that only think about money and increase the licences every year?

And @6Sense, what that have to do with anything? Are we here to talk about how i do business or discuss about CWP?
What i do and how I do it doesn't matter at all... im not comparing companies or websites, and that have nothing to do with the point. So... what is your point then?

So, is just silly to continue to deflect the questions and topics made.... kindle stop being a kid and think!

So: when will PHP 8.4 be released in CWP?

34
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 23, 2025, 10:21:46 PM »
cpanel envagelist (aka djprmf strokes) again with useless posts.

Since you do not use CWP, but cPanel why don't you go haunt their forums, or where you banned there for your BS..

Before make yourself look stupid, just read the thread....

https://forum.centos-webpanel.com/php/when-will-php-8-4-be-released-in-cwp/msg52603/#msg52603

Now, do you have any useful to say or will continue with pointless toxic behavior?

35
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 23, 2025, 03:08:06 PM »
The major work over the last year has been to transition out of CentOS 7 EOL and provide full support for EL8 distributions, with both a delayed repository (for CentOS 8 Stream) and for stable EL8 versions. This lays the groundwork for full EL9 support (which is currently in beta). So it's a big path forward after Red Hat pulled the rug out from under everyone using CentOS. Given this is Enterprise Linux, I would rather have a truly stable, long term supported foundation rather than shiny new features.

Do you realize that that announcement from Red Hat was made.... in 2020, right? 5 years ago?
and we know that CentOS 7 was to be in EOL by 2024 since that time...

In fact, CWP announce that at the time: https://wiki.centos-webpanel.com/the-future-of-centos-stream-with-cwp

Your point then is: is OK, they are working to continue support CentOS 7 (that is EOL), and CentOS 8 (that is also EOL)... and now working to CentOS 9. At this point, we can expect support to CentOS Stream 9 when he reaches the EOL date in 2027...
You don't see the issue here? Really?

They are supporting something YEARS after the EOL arrive. That is not providing a good product... is lacking in updates.

And for "shine new features", if you consider support recent versions of PHP or a simple firewall - heck, even a simple CSF update to the GPL version - as a "shine new thing" in a system...

36
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 23, 2025, 02:22:56 PM »
So... when will PHP 8.4 be released in CWP? :)

And that is where you get it wrong. Just because i have a company that provides cPanel to my clients, doesn't mean im and against CWP. In fact, i use CWP in MANY servers (from my clients and myself, to the hundreds in fact), and i don't need to have a public record in what i have done to them.... im not counting stars in a github repo to increase my ego.


The fact that i am stating that CWP is lacking in updates, is a fact. Im not dumb to state that everything is OK, when you cannot provide me ONE SIMPLE THING about CWP that have been done in the last 1-2 years! That is a fact...
And me stating that is not being a cPanel envagelist... is stating something, because i use CWP, and as much as any other user - including YOU - i don't want it to be a dead panel.

Masking the lack of updates doesn't solve the issue. If you wanna live in your digital world of fantasies, and continue dreaming that CWP is updated, that is fine.... But don't mislead users when is a FACT that there is no update for a long time, not even for a recent version of PHP or a firewall since the end of CSF... (and you know what panel doesn't also have a Firewall? Yes, cPanel!)

And that leads to the point of this topic - when is PHP 8.4 be release? a version that is already "out of date" but CWP not even have.

Also: if your point to not be "toxic" is be tracking my work as that is a point to something... are you stalking me? =)

What features are you wanting? Feel free to suggest it to their comment/bug report form. They are responsive there. (I for one do not want CWP to become as bloated as WHM and cPanel have become -- in an effort to include more and more features, their interface has become increasingly cluttered and difficult to navigate for end users.)

Im sorry, but are we talking about the same panel/team?

The developers that don't even acknowledge a security issue -  and DO NOT still to this day confirm it publicly.
Or the developers that are asked about the CSF EOL, and the response is "we are aware" and nothing else?
Or maybe the developers that still didn't update the panel to support PHP 8.4, when is already a new version out and 8.4 is already outdated?

Please, stop me when i am being a "cpanel envagelist".
Please, prove me that i am wrong....

37
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 22, 2025, 02:27:30 PM »
Are you the local cPanel evangelist? I'm tired of the Chicken Little weather reports about CWP -- "The sky is falling! The sky is falling!"

wow
Talk about toxic community...
what are you talking about,i don't even talk in cPanel or any other panel for that matter....

I just stating facts: CWP is out of date in updates to "new things". Am i stating something wrong?

38
PHP / Re: When will PHP 8.4 be released in CWP?
« on: October 22, 2025, 09:35:30 AM »
Probably a best bet looking for alternatives, since CWP appears a little death in new features...

39
What is the content of the .c file?

But yes, is related with the attack also.
The file contains a Base64 encrypted code, that do many changes in PHP files related with wordpress - theme and plugins.

40
If only CWP team had inform us about... Anything... 🤷‍♂️

41
CentOS 8 Problems / Re: packages update error AlmaLinux 8
« on: October 10, 2025, 01:30:26 PM »
Check:
ls /etc/yum.repos.d/

See if you have duplicated repos there or show here

The issue appears to be with amavis package.

42
CentOS 8 Problems / Re: packages update error AlmaLinux 8
« on: October 10, 2025, 12:58:27 PM »
Hi,

Try to do this commands in SSH:
sudo dnf clean all
sudo dnf update

if the error is still there, you can try to update anyway:
sudo dnf update --allowerasing

43
After that, anything can be changed realy. I notice some plugins changed, and theme files. Also there is a mu-plugin that is created to the redirect.

Location of those changes? Where can i find them?

The attacker have access to every file in your system. It could change anything...
I cannot provide you a "list" of what was changed in your case. Could be just the theme files, or nothing at all - some servers may still have the backdoor placed due to the exploitation of this vulnerability in CWP, but not "activated" - are there just waiting to a request that activates the malicious payload.

The WAF rules provided here can help, but don't fix the problem if your server is already affected.
The good news is that CWP already "silently patched" this vulnerability, so you should be safe from be attacked again if you use CWP.

I didn't check all the WAF rules provided here, but the request is activated with a specific query in a POST request made to the files placed in your server. If you simply access the files, they do nothing.
It should be a request like "domain.xxxx/defaiult.php?t=XXXXXXXXXX" - where XXXXXXXXXX is a specific query.

I did decode the files, and they install a webshell - thats it. What they do after that is from the attacker point of interest.

Unfortunately, if you have been affected by this, you have two options:
- Try to see the files that have been recently changed in your system. Not just the account that is affected, but ALL the system. After that, see if something was malicious changed.
- Don't consider the server safe. Try to deploy your accounts in a fresh new server - and make sure that every single website is also clean. Use something like WordFence, or more abroad, something like CPGuard to scan the accounts.

44
This is NOT a CWP bug.

PHP Injection Attacks will happen whenever.

You need to have your php.ini secured, and run ModSecurity with the latest OWASP CRS ruleset.
Along with running the latest PHP version you choose, 8.1, 8.2, 8.3 or 8.4

You'll also need to configured the OWASP base rules for services you run on that server.

NOTE: The CWAF ruleset is dead, and the last update was over a year ago.
Which is sad, this was a great ruleset.

For the PHP Injection Attack that has been going around, there has been fixes here how to clean up your PHP-FPM.

Sure, lets focus and talk.

Can you explain this sentence that you are providing in the quote text?
Kindly inform us how do you say that this is NOT a CWP security vulnerability and how do you get to that conclusion. Plese, don't refrain from use "tech mambo jambo", we are all sysadmin here after all :)

45
Information / Re: Is CWP still maintained?
« on: October 10, 2025, 12:25:58 AM »
Your arguments reek of being a straw man. Is Cisco's IOS open source? Do you use any of their products $$$$? Do they offer full transparency into their development process? And do their CVE publications present everything factually without any sort of distortion or positive spin?

I am a paying CWP Pro customer and am generally happy with the product. It is NOT open source -- it is IonCube encoded to protect their development efforts -- and I'm okay with that. This is a capitalistic arrangement through and through.

At this point, I'm ready to say, "Go back under your bridge."

Yes. Every single example that you give have a public change log.
Do you need examples?

Pages: 1 2 [3] 4 5 6