Author Topic: Hide CWP Name From Hackers  (Read 1937 times)

0 Members and 1 Guest are viewing this topic.

Offline
*
Hide CWP Name From Hackers
« on: April 30, 2023, 04:50:21 PM »
Hello All,

Hackers are running scripts against my CWP install, making my CWP security a big problem. I pay for the CWP Pro version, and I need help to disguise my admin login. I need to edit the login page and login css to remove the CWP logos, colors and some text.

I don't need to advertise to hackers that this is a CWP install. That just gives hackers too much information to work with.

Someone please tell me where the login and login css files are located. I can't even login to my CWP right now, because of some type of DOS attack that's happening right now... Please help me.


Offline
****
Re: Hide CWP Name From Hackers
« Reply #1 on: April 30, 2023, 10:34:35 PM »
Easier is to move the CWP admin port from 2030,2031 to some other port of your choosing. I am running an alternate port and don't use plain HTTP (2030), nor the cPanel port choices of 2086,2087 as with WHM. There are plenty of forum posts that detail this, as well as guides online.
https://azdigi.com/blog/en/webserver-panel-en/centos-web-panel-en/how-to-change-the-port-on-centos-web-panel-cwp/

Offline
*
Re: Hide CWP Name From Hackers
« Reply #2 on: May 01, 2023, 02:05:28 PM »
Thanks for your reply overseer. I was able to add 2 custom port numbers and then save the file. But for some reason when I ssh into the server and run the command, my new port numbers aren't there. I would still like to change my login page look... As I feel that's a good approach too.

Can you tell me where to find my login page in my CWP install?

Offline
****
Re: Hide CWP Name From Hackers
« Reply #3 on: May 02, 2023, 05:40:15 AM »
You meticulously followed that guide? There are others, too in case that particular one wasn't complete. Or you may need to restart CWP services and/or the whole server for the changes to go into effect...

Changing the CWP login look:
http://forum.centos-webpanel.com/index.php?topic=4756.0

Offline
****
Re: Hide CWP Name From Hackers
« Reply #4 on: May 04, 2023, 12:55:27 PM »
Or a simpler way is to remove them from CSF, and have your IP on the whitelist.

Any IP on the CSF whitelist bypassed the TCP_IN list.

Offline
****
Re: Hide CWP Name From Hackers
« Reply #5 on: May 04, 2023, 01:54:31 PM »
Definitely a simpler approach, but it doesn't work in my use case -- I'm still on D-S-Hell (DSL), so my IP changes constantly (sometimes more often than daily!)

Offline
****
Re: Hide CWP Name From Hackers
« Reply #6 on: May 04, 2023, 06:30:50 PM »
And your DSL provider won't sell you a Static IP?

WOW.

I know when I was with Xfinity & Spectrum they offer static IP's.

I'm currently using AT&T Fiber (1Gbps up & down) with a /29 IP allocation they charge an extra $10/month for.
But it's worth it.

Offline
****
Re: Hide CWP Name From Hackers
« Reply #7 on: May 06, 2023, 03:01:10 AM »
{Last} CenturyLink. Now they are called "BrightSpeed" after they went bankrupt. But someone needs to clue them in that they forgot the "Speed" part of their name. 15Mbit/900Kbit DSL is the best they can provide at my house. 20Mbit/1.8Mbit business class at my business address — 1500 ft from their C.O. building. Ugh! I refuse to pay them any more $$ for ANYTHING for 1999-era service. It's 2023 for goodness sake!

I almost went for Starlink, but fiber is currently being installed town-wide as a municipal fiber project. So I can get 100Mbit symmetric, or perhaps I will go for the mid-tier 250Mbit symmetric! (Gigabit is just too rich for my blood...)