Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - MyBuddyBen

Pages: [1] 2 3 ... 5
1
New Modules / Re: [module] Speedtest your server in 30 seconds
« on: July 15, 2020, 05:32:16 PM »
This still works  :D


2
PHP / Need to upgrade CWPPHP from 7.2.30 to at least 7.2.31
« on: July 15, 2020, 01:09:16 PM »
I ran a security scanner on the CWP service, and it noticed a DoS vulnerability in the CWPPHP

According to its self-reported version number, the version of PHP running on the remote web server is 7.2.x
prior to 7.2.31, 7.3.x prior to 7.3.18 or 7.4.x prior to 7.4.6. It is, therefore, affected by a denial of service (DoS)
vulnerability in its HTTP file upload component due to a failure to clean up temporary files created during the file
upload process. An unauthenticated, remote attacker can exploit this issue, by repeatedly submitting uploads
with long file or field names, to exhaust disk space and cause a DoS condition.

Solution
Upgrade to PHP version of CWPPHP in Yum to 7.2.31, 7.3.18, 7.4.6 or later.

Risk Factor
Medium

CVSS v3.0 Base Score
5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVSS v3.0 Temporal Score
4.6 (CVSS:3.0/E:U/RL:O/RC:C)

CVSS Base Score
5.0 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Temporal Score
3.7 (CVSS2#E:U/RL:OF/RC:C)

STIG Severity
15
I

References
CVE CVE-2019-11048
XREF IAVA:2020-A-0221

3
Other / Re: CWPPRO
« on: June 19, 2020, 05:38:45 PM »
You could try updating/forcing CWP to check for an update, and it may find your cwp pro license status. Be sure to have the proper IP address set for the CWPPRO license too

sh /usr/local/cwpsrv/htdocs/resources/scripts/update_cwp

4
PHP Selector / Re: How to add PHP 7.4 to PHP Selector 2 (CWP Pro)?
« on: June 01, 2020, 10:43:24 PM »
To be fair, cPanel just released 7.4 on their software, so if CWP adds it by the end of this month (June 2020) They would be doing great far as timing. Even though they said it would be by the start of 2020 which didn't happen, compared to cPanel they still have a chance to redeem themselves. But cPanel gets paid well... Buckets load more money and resources than CWP so take that into consideration.

CWP been good with keeping up to date for 7.3 with updates so far. Just hope to see 7.4 by the end of this month please.

5
New Modules / Re: [Module] CWP_2FA
« on: March 24, 2020, 12:49:25 PM »
Donating to CWP Support doesn't help rcschaff in any form whatsoever: I will repeat: he does not work for CWP support!
FYI: I put a small donation to CWP,prior to purchasing two CWP Pro licenses, plus I donate to, for eample Linux Mint. Occasionally, people donate to me for my given information - then again some forget. :-\
If you mean "If you would like to donate to the project, I accept donations.." i.e. at the github page, then great I applaud you.

Okay I see where you misunderstood from the start then. No I didn't mean donate to cwp support. I meant the actual rcshaff as I said in my first post. They have a donate link on the github page to anybody who actually reads the CWP_2FA readme page. So you just simply misunderstood what was meant in the first post I made.

If a moderator would like to remove all this drama posts, I won't blame you. The developer doesn't deserve this on his wonderfully made module! :) Best to the dev rcshaff! Keep up the great work and hope people donate DIRECTLY to rcshaff if that wasn't obvious enough. Best regards!

6
New Modules / Re: [Module] CWP_2FA
« on: March 23, 2020, 06:31:18 PM »

Wonderful work! :D Sent small donation to support! You guys this is a great module!

Use and support this guy! Hope he makes more modules for us to enjoy and we continue to support him!
One problem: rcshaff DOESN'T WORK FOR SUPPORT!
He done this "off his own back", to help others.

Wait... ?? lol You're down playing donating to a freewill developer?? If users donate out of appreciation for the hardwork done, you don't think that's supporting the coder? Alright alright not sure if you like donating or not, but I like to show support to people like rcshaff for the amazing work.  ::)  ;D

7
New Modules / Re: [Module] CWP_2FA
« on: March 20, 2020, 05:27:57 PM »
Video uploaded to the GitHub Page

Wonderful work! :D Sent small donation to support! You guys this is a great module!

Use and support this guy! Hope he makes more modules for us to enjoy and we continue to support him!

8
New Modules / Re: [Module] CWP_2FA
« on: February 23, 2020, 02:26:53 AM »
Interested in seeing some screenshots or video of this :)

9
Saden to see this hasn't been completed yet.. 02/03/2020

11
+1 this

We need PHP-FPM 7.4 support for CWP or CWP Pro



(Sidenote, your smilies for the forum are broken! example link for smiley : http://centos-webpanel.com/forum/Smileys/default/huh.gif ) Need to fix the smilies here on the forum ;)

12
Fixed method and I believe it works with these new changes.
ONLY KNOWN TO WORK WITH APACHE SERVER.. Unsure with APACHE + NGNIX or VARNISH.
But I know it works with just plain Apache selected as the webserver..

I wish I could modify my first post, but the moderators here don't allow you to edit old posts, even if you're the creator. Not a good thing in my opinion for stuff like this that needs updating.

Updated on 04/04/2019

How to install


---FTP method:


1) Upload cloudflare.php to CWP server in /usr/local/cwpsrv/htdocs/resources/admin/modules

Download cloudflare.php:  https://cwpaddons.b-cdn.net/install/cloudflare.php

2) Open URL: yourdomain.tld/admin/index.php?module=cloudflare
3) Click the Install button

---Console method:

1) cd /usr/local/cwpsrv/htdocs/resources/admin/modules
2) wget -O cloudflare.php https://cwpaddons.b-cdn.net/install/cloudflare.php
3) Open Url: yourdomain.tld/admin/index.php?module=cloudflare
4) Click "Install" button

13
Installation / Re: Cant issue SSL Cert
« on: April 08, 2018, 08:49:06 PM »
What domain are you trying to install AutoSSL for? Is it for the hostname? If so, then AutoSSL won't work for you that I know of. However, if it's for a different domain on the server, then it shouldn't be downloading the master.tar.gz to your /root/ folder in the first place. The .acme.sh/acme.sh I thought should be on the folder for the domain. So that's very odd.

Check with CWP support, and even pay the $7 one time support if you want expedited support.

http://centos-webpanel.com/support-services

14
Installation / Re: How to Enable Varnish for website
« on: April 08, 2018, 08:46:53 PM »
I thought X-Cache IS a varnish header. (https://docs.acquia.com/acquia-cloud/performance/varnish/headers) look at x-cache. Should show HIT or MISS if it is varnish.

15
Check the API log on the destination CWP server. See if it receives any requests via API.

File Management > CWP Log Viewer > Select API from dropdown.

Pages: [1] 2 3 ... 5