Recent Posts

Pages: [1] 2 3 ... 10
1
CentOS-WebPanel Bugs / Re: Test page centos hijack my facebook...
« Last post by overseer on July 21, 2026, 06:18:26 PM »
Also, you can change your Index directive in Apache or Nginx. I always set it to just index.php (removing index.html and index.htm) unless it is for a static HTML site (much more rarely these days).
2
The main thread regarding the gsocket hacking should have most of the details you need. Also the CWP-provided script should do a lot for you automatically. Do you need help cleaning up your server?
3
Hacker used CWP to get into server, not centos.
Not to mention that centos 8 is one of the OS that CWP recommends.

Anyhow, CWP was patched but hacker was already in.
Any suggestions on how to clean server?
4
Other / Forum's down for a long time
« Last post by Starburst on July 21, 2026, 02:24:07 PM »
I'm sure I'm not the only one who noticed the long downtime of the forums this latest time.

We have created CWP forums, as well as others at: https://sysadmin.help

No, we are NOT CWP. Only a Licensing Partner.

Right now, it's only a couple of us on there.
But hopefully it can grow and become an additional resource for all.
5
Any reason you're running an EOL OS (CentOS Linux release 8.5.2111)?

That OS isn't receiving any updates, and hasn't for a long while.
It reached EOL on December 31, 2021.

Stream 'replaced' it and then became Red Hat's beta OS.
Fedora (alpha) -> CentOS Stream (beta) -> Red Hat Enterprise (RHEL).

CentOS Stream 8 is no longer supported either.
It officially reached its End of Life (EOL) and End of Support (EOS) on May 31, 2024.

Neither receives security updates, bug fixes, or new package builds.

Running that OS is just asking for hackers.
CWP has fixed it on there end, but that EOL still has the vulnerabilities hackers can use.
6
I facing the same problem. Hacker have injected code in system files that make pages show different content to different users.
Found these entries in /etc/hosts
127.0.0.1 mya.cloudsyndication.org
127.0.0.1 gsocket.io
127.0.0.1 www.gsocket.io

and removed them. I restarted apache but nothing changed.
What else has to be done in order to remove all malicious code/files from server.
Running CWP  vesrion 0.9.8.1244  on CentOS Linux release 8.5.2111

Thank you
8
CentOS-WebPanel Bugs / Re: Test page centos hijack my facebook...
« Last post by Logician on July 20, 2026, 05:53:39 AM »
Removing index.html from /public_html/ MIGHT help.
10
CentOS-WebPanel Bugs / Re: Test page centos hijack my facebook...
« Last post by geodim on July 16, 2026, 10:24:10 PM »
Did you ever find a solution? I am facing the same problem!
Pages: [1] 2 3 ... 10