Recent Posts

Pages: 1 2 3 [4] 5 6 ... 10
31
Information / Re: New security issue? 09.09.2026
« Last post by comokoko on September 10, 2026, 11:34:32 AM »
Currently, many of my servers running AlmaLinux 9 and the latest version of CWP have been hacked using this method.

The attackers are gaining full root access; they are redirecting sites on the server to gambling sites, performing their own Google account verifications, and installing and running crypto-mining services in the background.

I hope CWP is aware of this issue; servers with up-to-date operating systems and the latest CWP panels are being compromised again.

We had previously reformatted and reinstalled the servers I am referring to because they had been hacked due to earlier CWP vulnerabilities, yet serious security flaws persist even in the latest version.

NOTE: This vulnerability is not the same one from previous months. It is a vulnerability discovered this month, as the operating systems and CWP versions on the servers are up to date; furthermore, the servers in question were reformatted and reinstalled approximately one week ago.
32
Information / Re: New security issue? 09.09.2026
« Last post by kadybee on September 10, 2026, 07:30:42 AM »
Yes, I've been battling this one for a few days now and looking for their way in.
It appears the test one is an initial probe and then the aby.php appears.  That appears to be a shell of sorts.

It then goes about infecting the site with casino redirects - thai or indonesian thing.

And here's a new one:  look for google domain verification HTMLs of the same date.  They are taking over domains into their own search console accounts.  Try finding somewhere/someone at Google to report this .. I haven't got very far in that endeavour!

I did note that a lot of the files were attributed to root.  In your /home directory run:  find . -user root |grep public
If you want a date as well:  find . -user root -printf "%-25p %t\n" |grep public

For the google verification files, run:  find . -name google*.html -printf "%-25p %t\n" |grep public
and check for recent dates.

I also noted files inserted into the wp-content/languages directory.

Will report back if I find anything more!





33
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by uma on September 09, 2026, 05:04:42 PM »
Further, Site loading properly in browser and view source code in browser is also proper.
But server is intercepting all web requests from bots that have "bot," "crawler," or "spider" so search result in search engine like Google
showing some other metadata instead of our websites data.

Refer similar thread at : http://forum.centos-webpanel.com/other/something-is-intercepting-bots-and-loading-a-different-page-for-them/msg54106/

34
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by uma on September 09, 2026, 11:58:37 AM »
Hello,

Using CWP since long and love it. I agree with @Netino and assume this issue occurred only after CWP upgrade it file manager.

Because issue occurred around after 10th Aug 2026 in my two server having CWPPRO on AlmaLinux 8 with latest Kernel, CSF Firewall, updated Apache, and
have Mod Security installed running the latest CWPPRO OWASP and does not have any WordPress installation  but then also both of my server affected.

In one of my server, all files and folders owner become root in public_html folder and in other server, lot many "cwp_login_randomnumber.php" files generated in public_html folder.
Screenshot attached.

I request to CWP that old stable version was perfect, No any demand for better look then why they update it?
I notice that look for CSF firewall page also changed, Old was far better and easy to use/maintain.

User require only functionality, secured updated supported version and fixes - Not themes and better looks.

If any one guide how to check infections and fix the issue greatly appreciated.

Once again I love CWP.


35
Information / New security issue? 09.09.2026
« Last post by comokoko on September 09, 2026, 10:33:50 AM »
hello

Today, I noticed a file named "test123zz" in the `public_html` directories of user accounts across many of my CWP servers; the owner of these files appears to be root.

I also observe that malicious files named "aby.php" and "vio.php" (And many .html files) were uploaded to the `public_html` directories at the same time as this file.

Seeing this same situation across multiple servers running the CWP panel led me to suspect that the issue might be related to CWP itself. However, if I open a support ticket, CWP asks for payment upfront.

Could you please check the `public_html` directories of the user accounts on your servers and confirm whether these files have been injected into your systems as well?
36
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by cyberspace on September 08, 2026, 08:50:34 AM »
Hi,

I checked my servers and found two hacked users. I'm not sure whether the accounts were hacked using the wp_autologin module, because there were requests to other CWP components before wp_autologin was called.

However, I found one interesting thing: the usernames of the hacked accounts exactly match a part of a domain installed on the server. For example, the following usernames would be unsafe: "mydomain", "addon2", and "com" if the following domains exist on the server: "mydomain.com" and "some.addon2.net".

Accounts with usernames that did not match any part of the domains installed on the server were not compromised.

So, I believe that the username must be known in order to exploit the vulnerability.
37
Hello CWP Community,

We would like to introduce JSNET CWP Billing & Hosting Automation, a billing and hosting automation platform built specifically for hosting businesses using CWP (Control Web Panel).

The goal of the project is to provide one system for customer management, billing, hosting provisioning, domains, payments and support instead of combining multiple separate platforms.

Main features currently available:

Customer and account management
Automatic CWP hosting provisioning after successful payment
Hosting service lifecycle management
Automatic suspend / unsuspend workflow
Invoice generation and payment tracking
Automated renewals and overdue handling
Hosting plans and different billing cycles
Domain search, registration and renewal
Nameserver and domain management
Payment gateway integration
Multi-currency billing
Client dashboard
Customer hosting service management
Invoice and payment history
Domain management from the client area
Support ticket system
CAPTCHA / anti-bot protection
TOTP Two-Factor Authentication
Audit logs
Built-in Site Builder
Built-in application update system
Central JSNET license validation

A typical automated workflow looks like this:

Customer Order → Invoice → Payment → CWP Account Provisioning → Active Hosting → Renewal Invoice → Overdue Handling → Automatic Suspension / Restoration

The public demo contains sample customers, hosting services, invoices, payments, domains and tickets so both the administrator and client workflow can be tested. External CWP, payment and registrar operations are simulated in the demo environment and demo data is periodically restored.

Live Demo

Demo: https://hosting.myjsdns.com/login
Front page: https://hosting.myjsdns.com

Administrator Demo
Email: demo.admin@jsnet.biz
Password: Demo123!

Client Demo
Email: demo.client@jsnet.biz
Password: Demo123!

Contact JSNET

Email: info@jsnet.biz
WhatsApp: +994 70 388 82 80
Website: https://jsnet.biz

We are continuing development and will be adding more integrations and automation features.

Feedback, feature requests and suggestions from CWP users and hosting providers are welcome.

JSNET LLC


38
Hi all!

Got hacked too.

I’ve noticed that the CWP team has done very little to help prevent these vulnerabilities.
On top of having backup issues for months, now we have this—something that distracts us from our actual work so we can deal with server problems instead.
Every server has issues, of course—that’s part of the job—but these system-level breaches are deeply concerning.

I have three servers and was planning to set up another one for a key client, but I’m rethinking that; I probably won't go through with it.
I’ve been using CWP for at least five years and love the panel for its speed and ease of customization, but things have been really bad lately.

We have to dig for information on the forum, which barely works; sometimes it won't load in Chrome (only Firefox), and other times it’s inaccessible from any browser.

The support tickets in the client portal are the only thing that really helps.

We pay for this panel; these basic services ought to work properly.

We are very disappointed.

Sorry for the rant.
39
Seems that reinstall cbpolicyd fixed it.
Thanks a lot
40
Suggestions / Eye icon
« Last post by luca on September 05, 2026, 07:43:35 PM »
Very common nowadays to have an EYE icon so you can click and see the pwd you typed in the login.
Can you add it? Would be invaluable.
Pages: 1 2 3 [4] 5 6 ... 10