Apache Proxy, cpanel services and vulnerability scanners
Hello,
We're seeing a ton of this nonsense from Google Ips, in short targeted vulnerability scanning and all proxy stuff:
grep "09/05/2026:14:47" /usr/local/cpanel/logs/access_log
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:20 -0000] "GET / HTTP/1.1" 200 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "X-Forwarded-For: _GOOGLE_IP_REDACTED_" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /400.shtml HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "-" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /400.shtml HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "-" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /asset-manifest.json HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "X-Forwarded-For: _GOOGLE_IP_REDACTED_" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /asset-manifest.json HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "X-Forwarded-For: _GOOGLE_IP_REDACTED_" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "-" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:21 -0000] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "-" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:22 -0000] "GET /assets/manifest.json HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "X-Forwarded-For: _GOOGLE_IP_REDACTED_" 443
_GOOGLE_IP_REDACTED_ proxy - [09/05/2026:14:47:22 -0000] "GET /assets/manifest.json HTTP/1.1" 500 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.36" "-" "X-Forwarded-For: _GOOGLE_IP_REDACTED_" 443
Excerpt from the cpanel log:
/usr/local/cpanel/logs/error_log:
[2026-09-06 00:47:21 +1000] warn [whostmgrd] Duplicate logaccess (GET /400.shtml HTTP/1.1): at /usr/local/cpanel/Cpanel/Server/Logger.pm line 91, <GEN12> line 2.
Cpanel::Server::Logger::logaccess(Cpanel::Server::Logger=HASH(0x44f6560)) called at /usr/local/cpanel/Cpanel/Server.pm line 1102
Cpanel::Server::body_internal_error(Cpanel::Server=HASH(xxxxxxxxx), 500, "Error ID 18cff0713d22b") called at /usr/local/cpanel/Cpanel/Server.pm line 1025
Cpanel::Server::internal_error_with_http_status(Cpanel::Server=HASH(xxxxxxxxx), 500, "Error ID 18cff0713d22b") called at /usr/local/cpanel/Cpanel/Server.pm line 1008
Cpanel::Server::internal_error(Cpanel::Server=HASH(xxxxxxxxx), "Error ID 18cff0713d22b") called at cpsrvd.pl line 1050
cpanel::cpsrvd::__ANON__(__CPANEL_HIDDEN__...) called at /usr/local/cpanel/Cpanel/Server.pm line 2651
Cpanel::Server::_block_login_if_brute(Cpanel::Server=HASH(xxxxxxxxx), "user", undef, "status", -1, "skip_hulk", 0) called at /usr/local/cpanel/Cpanel/Server.pm line 2611
Cpanel::Server::check_hulk_preauth_ratelimiting(Cpanel::Server=HASH(xxxxxxxxx), __CPANEL_HIDDEN__, 0, __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, 1787388023, __CPANEL_HIDDEN__, ...) called at cpsrvd.pl line 7193
cpanel::cpsrvd::docheckpass_whostmgrd(__CPANEL_HIDDEN__, __CPANEL_HIDDEN__, __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, undef, ...) called at cpsrvd.pl line 1850
cpanel::cpsrvd::handle_one_connection(4) called at cpsrvd.pl line 1214
cpanel::cpsrvd::script() called at cpsrvd.pl line 465
cpsrvd 18cff0713d22b: Missing required arguments! at /usr/local/cpanel/Cpanel/Server.pm line 2651, <GEN13> line 2.
[2026-09-06 00:47:21 +1000] warn [whostmgrd] Duplicate logaccess (GET /asset-manifest.json HTTP/1.1): at /usr/local/cpanel/Cpanel/Server/Logger.pm line 91, <GEN13> line 2.
Cpanel::Server::Logger::logaccess(Cpanel::Server::Logger=HASH(xxxxxxxxx)) called at /usr/local/cpanel/Cpanel/Server.pm line 1102
Cpanel::Server::body_internal_error(Cpanel::Server=HASH(xxxxxxxxx), 500, "Error ID 18cff0713d22b") called at /usr/local/cpanel/Cpanel/Server.pm line 1025
Cpanel::Server::internal_error_with_http_status(Cpanel::Server=HASH(xxxxxxxxx), 500, "Error ID 18cff0713d22b") called at /usr/local/cpanel/Cpanel/Server.pm line 1008
Cpanel::Server::internal_error(Cpanel::Server=HASH(xxxxxxxxx), "Error ID 18cff0713d22b") called at cpsrvd.pl line 1050
cpanel::cpsrvd::__ANON__(__CPANEL_HIDDEN__...) called at /usr/local/cpanel/Cpanel/Server.pm line 2651
Cpanel::Server::_block_login_if_brute(Cpanel::Server=HASH(xxxxxxxxx), "user", undef, "status", -1, "skip_hulk", 0) called at /usr/local/cpanel/Cpanel/Server.pm line 2611
Cpanel::Server::check_hulk_preauth_ratelimiting(Cpanel::Server=HASH(xxxxxxxxx), __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, __CPANEL_HIDDEN__..., __CPANEL_HIDDEN__, __CPANEL_HIDDEN__, __CPANEL_HIDDEN__, ...) called at cpsrvd.pl line 7193
cpanel::cpsrvd::docheckpass_whostmgrd(__CPANEL_HIDDEN__, __CPANEL_HIDDEN__, __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, undef, __CPANEL_HIDDEN__, undef, ...) called at cpsrvd.pl line 1850
cpanel::cpsrvd::handle_one_connection(4) called at cpsrvd.pl line 1214
cpanel::cpsrvd::script() called at cpsrvd.pl line 465
cpsrvd 18cff0713d22b: Missing required arguments! at /usr/local/cpanel/Cpanel/Server.pm line 2651, <GEN14> line 2.
We have whm and cpanel ports closed in our firewall, it appears that the requests are actually travelling via Apache.
The <Proxymatch> line in our conf file shows:
<Proxymatch ^https?://127\.0\.0\.1:(2082|2083|2077|2078|2079|2080|2086|2087|2095|2096)/>
My understanding here is that Apache has a rule matching proxy requests destined for 127.0.0.1 on cPanel/WHM-related ports.
My cPanel/WHM server's /usr/local/cpanel/logs/access_log contains entries where external clients appear as proxy (shown above), and Apache has proxy_module, proxy_http_module, and proxy_wstunnel_module loaded. Is this normal for a standard cPanel installation?
This seems to be what's happening:
Scanner requests arbitrary URL
Apache receives it on :443
cPanel proxy rules match
Request gets sent toward a cPanel service
cpsrvd doesn't get the arguments it expects
"Missing required arguments!"
cpsrvd generates HTTP 500
500 Error ID 18cff0713d22b
Missing required arguments!
For an arbitrary external HTTPS request that produces both a 404 and a subsequent cPanel 500 with cpsrvd: Missing required arguments, what is the exact request-processing path?
Does Apache's Proxymatch rule forward the request to a local cPanel service, and if so, why does the request produce both 404 and 500 responses? And crucially, can an unauthenticated Internet client send a request to my public HTTPS endpoint that causes Apache/cPanel to proxy the request to any of the localhost ports listed in these Proxymatch directives?
The particularly important thing for us is to establish whether the external requests are being passed through cPanel's legitimate proxy mechanism and whether they are reaching WHM/cPanel itself or merely producing errors.
I'm keen to try and shut this down, it really is getting on my nerves now.
Is anyone else getting this too?
Thank you.
-
You can use fail2ban to exclude all ip's reported in those logs for x period time i cut the traffic with this by 2/3
0 -
ProsySubdomains would forward the request to the cPanel service, so that would be a good explanation for what you're seeing: https://docs.cpanel.net/knowledge-base/general-systems-administration/service-and-proxy-subdomains/
0
Please sign in to leave a comment.
Comments
2 comments