Server hit by CVE-2021-41773
I was scanning all of my clients' servers for suspicious crontab entries as described in this article:
Do you guys have any recommendations for scanners to see what else may have happened? Are there built in scanners in cpanel aside from clamav? Has anyone tried Lynis, or know anything about them?
-
I installed clamav from the WHM dashboard, and when I went to run it I got the following message: # /usr/local/cpanel/3rdparty/bin/freshclam ClamAV update process started at Mon Nov 22 17:47:24 2021 WARNING: Your ClamAV installation is OUTDATED! WARNING: Local version: 0.101.5 Recommended version: 0.103.4 DON'T PANIC! Read https://www.clamav.net/documents/upgrading-clamav main.cvd is up to date (version: 62, sigs: 6647427, f-level: 90, builder: sigmgr) daily.cvd is up to date (version: 26361, sigs: 1947102, f-level: 90, builder: raynman) bytecode.cld is up to date (version: 333, sigs: 92, f-level: 63, builder: awillia2)
Is there a reason that cpanel would be installing an older version? Is this a copy meant specially for cpanel, or is it safe to update it to the latest? Thanks. Edit: when I look in yum it does show the newest version, but it doesn't think clamav is even installed, so it does appear to be specific to the cpanel plugin version of clamav. Any idea why that would be out of date? I don't see a way to update it in cpanel, it just shows that it uses the older version. Edit #2: Are there any issues with running OSSEC+ on a cpanel machine? Does anyone have any experience with this? Thanks. -Michael0
Please sign in to leave a comment.
Comments
3 comments