Recent Posts

Pages: 1 ... 4 5 [6] 7 8 ... 10
51
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by cyberspace on July 06, 2026, 06:50:51 PM »
If you like cPanel and the price $40+ /month is acceptable for you then use cPanel and stop spamming this forum.
52
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by cyberspace on July 06, 2026, 06:09:46 PM »
There were statements because openssl and glibc are life critical libs. They are used by bank systems, government, etc.

cPanel doesn't make statements about every vulnerabilities.

cPanel made statements about the vulnerabilities discovered in May because there were more  than 40k hacked cPanel servers.
53
CentOS-WebPanel Bugs / Re: 🚨 CWP new security issue - and no communication
« Last post by cyberspace on July 06, 2026, 05:53:16 PM »
Your comparison makes me smile. Don't you think it isn't reasonable to compare cPanel ($40+/month) and CWP ($1/month if PRO license)  ?

I active cPanel user (admin) more than 20 years. It has a mail "bug". The bug is actively used by spammers if they have success to hack some outdated joomla,wordpress,prestashop... website. cPanel developers knows about it but they haven't fixed it. up to now. In their logic: this isn't a bug this is "feature" :)

Quote
And answering your question: yes, i think me and anyone with any tech knowledge WANT to see a full changelog of everything that changed. In fact, here in Europe, is LAW... so...

You make me smile again. Look here:
https://control-webpanel.com/about-us
(scroll down and look at "company").
Do you mean "Europe Union"  when you write "In fact, here in Europe" ? If so then I don't think Georgia is a part of EU and it means you have answer on your question about law in Europe )
54
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by djprmf on July 06, 2026, 05:42:23 PM »
Yes, every software can and will have vulnerabilities...

... but most of them notify the users about it and NOT silently patch the issue.
ALL the software that you stated, every single one of them... there WAS a statement from the developers about the issue.

Do you have ANY security fix statement from CWP dev team? to ANY vulnerability?
55
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by cyberspace on July 06, 2026, 05:39:12 PM »
Any software has vulnerabilities. Some of them live more than 10 years: glibc: GHOST, Shellshock... etc.

That is why it is critically important to update all software but it doesn't make your system 100% safe.
56
CentOS-WebPanel Bugs / Re: 🚨 CWP new security issue - and no communication
« Last post by djprmf on July 06, 2026, 05:32:24 PM »
@cyberspace

Every single panel that i know provide a list of ALL the fixes made...
And even more, when there is a critical issue, most of the provide a full detail information of what is happening... not silence.

Do you need a example? Just look to the recent cPanel fiasco - the patch was not even lauched and there was a security notice in the blog providing FULL details about the issue... or just something that provide info to the users.
That IS common practice.

And answering your question: yes, i think me and anyone with any tech knowledge WANT to see a full changelog of everything that changed. In fact, here in Europe, is LAW... so...
57
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by djprmf on July 06, 2026, 05:29:57 PM »
@cyberspace

Please, don't try to deflect the issue - and even worst, try to deflect that issue to the users.

The vulnerability, before being patched, was active and was capable of being exploited... In true, that doesn't mean that THIS particular issue in this topic WAS because of this, but is just too much coincidence.
Lets just remember that there WAS another critical security issue in CWP, that WAS exploited, with multiple servers hacked... and we still don't have ANY info from the dev team about what happend... not even "sorry".

Even if is currently patched, that doesn't mean that some servers didn't get exploited BEFORE the patch was issued...
58
CentOS-WebPanel Bugs / Re: 🚨 CWP new security issue - and no communication
« Last post by cyberspace on July 06, 2026, 05:29:23 PM »
I know—you want to see a long list of entries in the changelog, right?

But I don't think you'll find anything more detailed than "security fixes" in the changelogs of cPanel or most other commercial control panels. It's common practice.
59
Other / Re: Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
« Last post by cyberspace on July 06, 2026, 05:25:53 PM »
Well, sorry to say that you are the first known victim: https://forum.centos-webpanel.com/centos-webpanel-bugs/cwp-new-security-issue-and-no-communication

Don't mislead users. The links you provided point to pages describing vulnerabilities that affect Control Web Panel versions earlier than 0.9.8.1225.

The current CWP version is 0.9.8.1243.

So what's your point?

If you choose not to keep your system up to date, that's your responsibility. Also, just because a server was compromised doesn't mean it was hacked through a vulnerability in the control panel. The actual cause could just as easily be Joomla, WordPress, or some other software installed by the user. Don't you think that's a more reasonable assumption?

You're making a lot of noise.
60
CentOS-WebPanel Bugs / Re: 🚨 CWP new security issue - and no communication
« Last post by djprmf on July 06, 2026, 05:25:44 PM »
@cyberspace

You completly miss the point, don't you?
Pages: 1 ... 4 5 [6] 7 8 ... 10