cPanel 130.0.16 cannot to upgrade to the protected version?
This is my environment:
Yesterday morning I received several warning emails about login attempts. I had previously had my root password stolen, and there were even instances where my hard drive showed abnormal storage capacity.
I just want to ask what version I can upgrade to if I want to upgrade now? Will I be able to get protection?
-
HATANO KENJI - what errors do you receive when trying to update the server's cPanel version?
-1 -
After that, I completed the upgrade of CloudLinux v8.10.0 STANDARD kvm + cPanel 130.0.19.
The ioc_checksessions_files.sh script is showing up correctly, but I'm not sure if my current version can resolve this security issue?
Or do I need to install a completely new environment to truly solve the problem?
0 -
Does the script show that there was a compromise on the machine? If so, it's best to create a new system and restore your data from backups if you have them.
0 -
I was hacked before, but I worked hard to modify the settings and I was able to use it. Can I use the free ImunifyAV scan to confirm whether the host environment is safe? (Scan all files in the system)
0 -
No - you would need to use the tool in the article linked above to confirm this particular compromise.
0 -
I received this information, but I've already changed the password and it's now using very long characters and random symbols, I also cleared: /var/cpanel/sessions/
Is it possible to preserve the server environment given my situation?
[*] Scanning session files for injection indicators...
[!] CRITICAL: Multi-line pass value detected: /var/cpanel/sessions/raw/root:*****[!] INDICATORS OF COMPROMISE DETECTED - IMMEDIATE ACTION REQUIRED
1. Purge all affected sessions (rm -rf /var/cpanel/sessions/*)
2. Force password reset for root and all WHM users
3. Audit /var/log/wtmp and WHM access logs for unauthorized access"
4. Check for persistence mechanisms (cron, SSH keys, backdoors)0 -
The best thing to do when a root compromise is detected is to create a new server and restore your data from backups.
0 -
As you know my situation, I may not be able to get direct help from the web hosting company.
But if I get the CloudLinux + cPanel license transfer, can you help me redeploy it?
Because of my limited technical skills, I find it difficult to quickly and correctly reset all server settings.
I need your help.
0 -
I wouldn't be able to answer that definitely without seeing what backups you have available. If your license was purchased with us you would be eligible for our support, yes.
0 -
I have formally requested a license transfer from my web hosting company.
If I am granted the necessary authorization, I would appreciate it if you could help me revert the modified WHM settings in the latest version.
Because no matter how I modify it, the hacker seems to still be able to execute related malicious virus code deep within the system, which is beyond my capacity to handle.
Please offer us help in our time of need.
0 -
If the server has already been compromised there isn't going to be much we can do on our side except confirm the issue. There isn't a way to fully "clean" a compromised system, so migrating to a new machine is the best option.
0 -
Can I directly transfer the WHM settings that I have already completed?
The setup I've already completed is a miracle for me. According to Google AI's reply, everything I've done is a perfect setup. The problem is, I don't know how to start the same process again.
At the very least, I need your company's assistance in restoring my important server configuration files and automatic scheduling scripts to the new server environment. =.=
0 -
I suppose it would depend which settings you're referring to. Most settings can be copied by running the https://docs.cpanel.net/whm/scripts/the-cpconftool-script/ tool mentioned here, with explanations on how to backup and restore them.
0
Please sign in to leave a comment.
Comments
14 comments