Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - djprmf

Pages: 1 2 3 [4] 5 6
46
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 10:02:40 PM »
You guys seem to like to use something without any transparency about what you are using... And that is ok because it's free. Makes sense I guess ‍♂️

47
Hi 6sense.

https://forum.centos-webpanel.com/informations/is-cwp-still-maintained/
Read the topic.

You cannot take seriously someone that don't know the difference between a PHP exploit and a exploit in a implementation of the code in a application.

He could be a great person, but doesn't know what is talking and is misleading others.

Is ok to say that you don't know something.it is NOT OK to provide false information. And that was what he have done the entire time.
So yes,I provide proofs and knowledge,things that ANYONE CAN SEE AND KNOWS.

not a word from someone...

Bit is simple.prove me wrong....

Then take your conclusions...

48
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 06:29:59 PM »
And i found out this: https://control-webpanel.com/changelog

The last "update" in what was really changed was in version 0.9.8.1188, released in 13/11/2024.
After that there is updates, but no one knows in what.

And this is the OFFICIAL WEBSITE of CWP. Is not me, is not made up. You CANNOT provide any info about what was updated after 13/11/2024 besides numbers that increase in the CWP panel.

If you don't see any issue in this lack of transparency, just because "is free"... oh boy.

49
Starburst already gave the answer above:
You need to have your php.ini secured, and run ModSecurity with the latest OWASP CRS ruleset.
Along with running the latest PHP version you choose, 8.1, 8.2, 8.3 or 8.4
And he has guides for updating ModSecurity and the OWASP CRS ruleset (tested on both AlmaLinux 8 and 9):
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-12-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-running-cwp-and-apache-on-almalinux-9/

Those guides are pointless for this issue.
They are to protect the websites, not the CWP itself. The RCE was a exploit in the CWP file manager, not in the websites.

Kindle don't provide false information, and dont mislead users to somethint that is not. You don't appear to even know what is a exploit... even less to provide info about waf protection rules - that, again, DO NOTHING about this issue in CWP.

50
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 06:17:39 PM »
Just because the product is free that doesn't mean that security issues should be hidden.

You are literally saying that is better to have a SECURITY ISSUE, in a control panel that many use in they servers, just because "its free". That is NOT a good answer to give, and not a very good idea to have if you manage any kind of server - even more if you have clients in it.

Just because something is "free" doesn't excuse everything. And a security issue is not something that should be hidden.
Anyone that think other wise doesn't know anything about server management and should not be consider a sysadmin - that is a fact in the industry, not something made up by me...

Are you for real? I know that people that use CWP not always have the biggest knowledge about server management and sysadmin in general - and that IS FINE. But have people say that it is better to have security issues hidden than disclosed... is just ridiculous.

And i read that sentence over and over again: "go to other panel". Do you understand that, if everyone does that, CWP just cease to exist, right? The panel that you are supporting here... you are not helping at all with statements like that.
And is not a first thing: Sentora was one example.

In fact, im helping here more that anyone else that comment: transparency MUST be something that should be in EVERY SINGLE action of a project. That is A FACT. If you hide something like a security issue, just because is Free, you are doing it wrong.


Also, @Starburst, kindle stop providing false articles about WAF protection when you clearly don't know what they do. WAF protection is to protect against potential attack vectors - like exploits. You CANNOT apply WAF rules in the CWP - your guide is to apply to the website in the servers, that is pointless (and you know why? Exactly, because the exploit here WAS IN CWP, not in because of the websites in the servers with CWP).

51
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 01:32:24 PM »
The RCE with CWP wasn't fixed? And by who?
Or now CWP doesn't uses PHP anymore? By your logic then.... this isn't fixable, since is a "PHP Thing"... so....

52
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 01:26:13 PM »
Then, by your logic, we should blame the creators of the binary... because they created this digital thing.
Or we should blame the creators of guns... not who use them and for what...

You don't really see how your logic makes no sense?

53
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 01:06:12 PM »
dude, no one is blaming CWP for the RCE... that is a PHP thing, exist since PHP exist...

What you don't understand that is NOT *the* vulnerability, but the LACK OF INFORMATION to acknowledge the vulnerability from the CWP side?

CWP had a vulnerability. THAT IS FINE.... if they fix it and disclosure it.
They fix it. Great!
But the disclosure? NO!

Every single one of the panels that you state HAVE disclosure the vulnerability in they software. Because - and again, becase you apparently cannot understand this - THEY ARE RESPONSIBLE FOR THE SOFTWARE THAT THEY CREATED!

CWP did not disclosure that. They prefer hide it under a "update", that you don't even know what is. Or do you have a changelog for the versions lauch?


54
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 12:53:34 PM »
TLDR: If you develop something, you ARE responsible for the security of that thing. Just because you have an error in the code, security issue, or anything in the thing that you develop, that doesn't make you any less responsible for it.
yes, you should fix it. But if is something that OTHERS WILL USE, you should ALSO report that to everyone, not sweep under the rug....


And no: you cannot excuse the issue just because others had it. That is not any of this works.... never had been.

55
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 12:45:33 PM »
Your post makes no sense.
All you have done is link to many RCE vulnerabilities in different applications - some dated 16 years ago. What have that to do with anything?

No one is saying that RCE is a "new thing"... is a security issue, and yes, if has happend before in different aplications... but what have that to do with the LACK OF COMMUNICATION from CWP, about the RCE issue that happend in the control panel.

Those links have nothing to do with the CWP situation.
Or are you stating that just because RCE is a thing, CWP shouldn't be blamed because of it?
For that logic, every attack, malware or exploit have a excuse: "oh well, it happend to others, so..."
Do you see the fault in your logic?


The point here is that CWP did NOT acknowledge the security issue, not even a post to alert the administrators about it. Not even in the post that was created by a forum member to alert.
Can you provide some way in HOW they confirm the issue?

So yes, CWP is to blame. They fixed, but silent fix a security issue is NOT the way that any credible company does this - and you should know that!


And about the other issue, @Starburst, you can be whatever you want to be. You can be a CWP partner... but you ARE NOT CWP.
Again, you are making no sense... How i was spreading misinformation?
  • You are just a forum member? Yes
  • You provided false information about in how CWP had nothing to do with a security issue in they panel? Yes
  • You are trying to prove that just because RCE exploits exist - had had FOR YEARS - that somehow make CWP team not responsible to disclose a security issue in they panel? Yes.
  • You are a CWP Partner? Yes
  • You are NOT a CWP team member, so you cannot talk for them? Yes

Is anything here wrong?

In fact, your response about all this is troubling, because you cannot call you a sys admin and state that every exploit in a software should be "excused" just because "it exist"... That is NOT how this works...

You are a forum member, that's it. You are not the entity responsible for the CWP development, and you don't have any say or do in how CWP is developed. Only the CWP team has, and to this point, no one is talking anything.
at best yes, you are a CWP partner... but STILL NOT A DEVELOPER of the CWP team.


56
Information / Re: Is CWP still maintained?
« on: October 09, 2025, 12:00:33 PM »
@Starburst You are going offtopic - that is not the point here. I stated that in the previous message exactly to reinforce the point.

The fact that you are providing KB articles, and NOT the CWP team, is the problem here. You are NOT the CWP team...

And you left back the questions: you KNOW what changed in the updates? Do you know anything that is made in every update?

I see that you provided false information in the CWP exploit topic, stating that it wasn't a CWP exploit.... when it was.

This alone shows how little comunication is made from the team.... is a random member in the forum that is providing the information without any "official" knowledge of what is happening.

Is great that you are trying to help anyone around here, and great if you have the back for that as a sysadmin... but you are NOT the CWP team and cannot make sentences for them about the control panel, because is NOT your own creation/development.

57
It can vary from installation to installation.
In some, the backdoor stays dormant in the server, waiting to be "activated" - the file placed first is just a exploit, to create the webshell file if access with a POST request and specific queries. If the request is done, the file "defaiult.php" is created, and that is the real webshell file.

After that, anything can be changed realy. I notice some plugins changed, and theme files. Also there is a mu-plugin that is created to the redirect.

Of course, data in the BD and other details, like the WordPress configuration file, are also changed/access. If you have any password or WordPress salt in there, change them. But at this point, the installation in your server should NOT be considered safe.
You can still use it... but at your own risk.


58

As far as I could see, this attack was only able to compromise non-sudo accounts. Through trial and error (using combinations of domains related to the server), the attacker only needed to find one valid user. Once that happened, he was able to discover other usernames to exploit additional non-sudo accounts.


The file dropped in the directory was a web shell. The attacker indeed have interest in change the webpages to a pseudo store, but with the webshell, he can have access to any account in the server, and any file on it - including the way of change any system file or configuration.

Yes, the exploit starts with a non-sudo user, but can change any other file on the system. If that happend or not... is complicated to know.


In the worst-case scenario, the attacker was able to explore the server in read-only mode — likely dumping databases, backup files, SQL user credentials, and so on, across the entire system.
Non-sudo accounts should not have read access across the whole system, even the /etc/shadow file is readable with them.
Write access was only possible within the affected users’ home directories, including the /tmp directory.


With the webshell, you can have full access to the system, unless you have some way of mitigate that - like Cloudlinux does. They have a virtual filesystem to every users, so even if the website is exploited with a webshell, the attacker can only see the virtual root filesystem, not the actual system.

CWP doesn't have that. With a webshell, they can see and edit or send any command to the server.
If you use the CWPSecure kernel, i don't know if they have that protection. But i bet most of the servers don't use that.


Regarding WordPress what happened to your websites? Mine were defaced with a fake drop-shipping-style store, and the results got messed up in Google Search. Usually, these deface hacks are triggered when the referrer is Google, but this one didn’t behave that way. I only discovered it's real face by simulating a Googlebot user agent in my browser.
The wordpress code got so messed up that I can't even find where the infected code is. I'll have to reconfigure a brand new installation.

It looked like this:
https://i.imgur.com/zn6ji93.png

Yes, the exploit appears to be target to wordpress websites. The file that actualy deploys the exploit can be dormant in the system for months, and only activated when the attacker sees it. Is a fake JPG file with PHP code in it.

59
Since this WAS a vulnerability in CWP, there is no point in considered that if a server was affected, there is no backdoor still installed.

The report is here: https://fenrisk.com/rce-centos-webpanel

So, if you are still in a server that have been compromised, there is no way around to know what have been done. Remove the files can be suficient, sure. But you don't know if anything else was compromised.

The information that this is a fault from PHP, WordPress or some script in the user server are not true. If you see the files stated in the first message in your accounts, your server was exploited due to the CWP vulnerability.

Also: we are still waiting for any information related to this by the CWP team.

60
Information / Re: Is CWP still maintained?
« on: October 08, 2025, 02:41:11 PM »
Again, the PHP Injection Attack, had nothing to do with CWP.
But happened to older servers that where not updated and their PHP hardened.

PHP Injection Attacks are common by script kiddies. And just don't happen to CWP.
GoDaddy's servers are constantly getting hacked, which are using Amazon AWS. lol

There are several articles out there on has to secure you php.ini config.

That is NOT true.
The issue WAS a vulnerability in CWP. Is NOT fault from the users.

https://fenrisk.com/rce-centos-webpanel
https://gbhackers.com/centos-web-panel-vulnerability/

So not, wasn't the users fault. it WAS a vulnerabilty in CWP.


Pages: 1 2 3 [4] 5 6