Is cPanel involved in all cPanel hacks?
I opened several support tickets to cpanel regarding this problem and everytime they are changing the subject.
All my tickets regarding this problem, were diverted to different subjects, like they forgot why i contacted them.
I will be as short as possible.
Since about 15 months ago, my server started to get at account level and a few days at root level.
Everytime my servers were using the tool from anonymousfox.com
is very simple. You upload that tool anywhere in the server (mostly using an wordpress vulnerability or file manager and with a press of a button you get to see all the password of users from server).
You get to see all the files and you can even login bypassing two factor authentification.
Mostly, hackers don't use interfaces, i believe they use some APi scripts or something, because these attacks are random and they don't spend the time to manually login to each account.
however, the script allows you to infect the entire server and every file, using a click of a button.
before claiming that i should improove security, here are some of my setups:
- Simlink protection is on
- simlink sameuser is on
- two factor authentification is on
- ssh is on different port and port is blocked by firewall
- i use mod_ruid2 + mod_security and all needed securities at apache level.
- jail_apache is activated
- no user has shell access
- cphulk is activated and logins from other countries than mine, are prohibited.
- kernel care simlink protection
- CSF + CXS installed and configured into server
- imunifyav active
- cookie ip validation set to strict
So you can imagine the level of security for the server.
With all these securities, my server was still with that tool.
I get it that the way that tool ended-up on the server, is a problem of website vulnerability.
But, everything else should be isolated. If a customer decide to harm the entire server, he shouldn't be allowed by cpanel. maybe there is no vulnerability, but a customer decide to hack the server, why is this possible?
If one user has that tool, the hacker gets access to the entire server.
Its been 15 months since i seen this and reported to cpanel and all of my tickets ended without any resolution.
My beliefes are that cPanel want these hacks to happend, because if you pay enough money to their support and if you pay enough money on tools they sell on cpanel.net , they secure your server enough.
Otherwise i can't understand why they turn around and pretend that i didn't told them about this problem and mostly they end the tickes for reason "you did not answer to the ticket"... after a few hours after they send a reply which sais "i will get back to you soon".
I now have an abandoned server created for test using centos web panel and its been 8 months and no hack on that server.
i wonder why a test abandoned server don't get and a cpanel with many customers and that worth some money is .
What do you think about this? did you get this kind of problem and cpanel never wanted to fix the bugs claiming that is "an wordpress matter, not a cpanel one" ?
here is one of the answers i received after i explained to them everything of how the server was and that cpanel has bugs:
Except as explained in this notice, cPanel, LLC has a policy against providing technical-support services concerning server security. Based upon the information you submitted in your recent technical support ticket, we believe--but caot be sure--that your incident is a server security-related incident. Because of cPanel's prohibition against providing technical support concerning security issues, we caot assist you with the resolution of your support incident. We recommend that the server is analyzed by a qualified systems administrator or security researcher.
Since this message, my server was 4 times more. so no bug fix yet.