Skip to main content

cron to generate new remote access key

Comments

5 comments

  • cPanelMichael
    Hello :) Thank you for taking the time to share this with others on the forum. The best way to address this issue is to determine how the account is getting hacked and take steps to prevent it from happening again. Is there a specific feature you feel would be helpful when this happens? Thank you.
    0
  • Jcats
    Well its your typical WP hack, out dated plugin, etc, I was merely just pointing out the way they were able to keep generating a new hash with a PHP script. I don't personally know what or if something could be put into place to prevent that, I figure I would just share and let you guys with the brains decipher if there is anything that can be done, if not, then at least others can be aware of the possibility.
    0
  • quizknows
    Impressive hack to maintain access, thanks for sharing.
    0
  • lx24
    That's call eagle eye..Reading logs aint joke..
    0
  • cPanelMichael
    By default, resellers have privileges that allow them to setup a remote access key. One potential feature request you could open would be to include an option to limit the ability for resellers to setup remote access keys. That being said, in the meantime, for anyone that notices an account is hacked, it's always a good idea to review cron jobs configured for an account after it's been hacked in addition to any new files uploaded or changes made to existing files. Thank you.
    0

Please sign in to leave a comment.