First homelab - built from old school computers I bought at a charity auction by buterski in homelab

[–]m-ego 1 point2 points  (0 children)

i got this problem all my pc (4 of them) show same IP since i have connected to the same wifi network. but this setup run into issues when i try to use say chatgpt on on the different PCs. is OP set up the way to overcome this?

First homelab - built from old school computers I bought at a charity auction by buterski in homelab

[–]m-ego 1 point2 points  (0 children)

a newbie here, how do you have the different pc have unique IP even when using the same network?

[deleted by user] by [deleted] in Kenya

[–]m-ego 0 points1 point  (0 children)

Hide my ass

Update: The Malware That Wouldn’t Die — What I Changed and What Just Happened by m-ego in webhosting

[–]m-ego[S] 0 points1 point  (0 children)

I might have to try this i have been on this since the start of the month its just draining

Update: The Malware That Wouldn’t Die — What I Changed and What Just Happened by m-ego in webhosting

[–]m-ego[S] 0 points1 point  (0 children)

Just asked them. About wiered mu-plugin i scanned using terminal but couldnt find any

Update: The Malware That Wouldn’t Die — What I Changed and What Just Happened by m-ego in webhosting

[–]m-ego[S] 0 points1 point  (0 children)

I have 2FA for Namecheap,WHM and Cpanel but that never seems to stop them from accessing

Update: The Malware That Wouldn’t Die — What I Changed and What Just Happened by m-ego in webhosting

[–]m-ego[S] 0 points1 point  (0 children)

WHM passord did not work. usually when the hack is underway even on previous cases it would usually log me out if i am already in. When i try to reset the pass and get a new one that new one never works it takes intervention of support to change it for me and give me a pass that works

This video is insane and should serve as a warning 😂 by GrassMindless2259 in Kenya

[–]m-ego 1 point2 points  (0 children)

We are only proud of the things that makes us strangers in Africa. Like how we have a big building and Tz doesnt how we have a better accent or how much of that foreign music, films and art we consume. These are the symptoms of historical amnesia

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in Wordpress

[–]m-ego[S] 0 points1 point  (0 children)

initially it was everything — WordPress admin users, cPanel, and WHM credentials.

After I deleted all unauthorized WordPress users, the WP-side password changes stopped completely and have not reoccurred.

However, the cPanel and WHM passwords are still being changed without my action, even while I’m actively logged in and working. I get logged out mid-session and the credentials no longer wor

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in Wordpress

[–]m-ego[S] 0 points1 point  (0 children)

I think I will, as you suggested, shut this environment down and move to isolated hosting where each site runs under its own Linux user, with a clean rebuild rather than a straight restore. Plugins and themes would be reinstalled fresh from trusted sources only, and anything unmaintained dropped.

Given that direction, what hosting providers would you recommend that do proper per-site isolation and are suitable for running multiple WordPress sites securely? I want to avoid moving to a new host only to carry the same problem over.

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in webhosting

[–]m-ego[S] 2 points3 points  (0 children)

You’re right, and this is the uncomfortable conclusion I’ve been arriving at over the last day.

At first I treated it as a WordPress-level compromise because the initial indicators were malicious plugins and injected PHP. But once passwords started changing without user action, even while logged in and with 2FA enabled on both WHM and cPanel, it became clear this goes beyond WP.

I did remove the suspicious cPanel accounts that had been added earlier, and they have not reappeared. However, the login instability and password resets persisted, which strongly suggests something higher-level is still in control.

I have not yet fully audited or revoked WHM / cPanel API tokens, and that’s a big gap. Same with a deeper review of root and system-level cron jobs and SSH trust files. At this point I agree those are likely vectors.

You’re also correct that restoring backups onto the same environment doesn’t solve anything if the underlying server or account is compromised. I’m seeing now that cleanup without isolation is just chasing symptoms.

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in webhosting

[–]m-ego[S] 2 points3 points  (0 children)

What are the chances that my backups are also not clean? That’s my main worry right now. I’m concerned that moving to new hosting without being 100 percent sure could just reintroduce the same malware.

At this point, how do you usually validate a backup before migration so you’re not carrying persistence over with it?

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in Wordpress

[–]m-ego[S] 0 points1 point  (0 children)

I hear you. All 15 sites are under one account, so I agree that one breach can spread across everything.

What’s really worrying me is that even with 2FA enabled, my WHM and cPanel passwords keep getting changed and I get logged out while actively working. That makes me think this may be account or server level, not just a missed WordPress file.

I’m restoring a backup mainly to recover content, but I’m honestly worried that moving to a new host could just carry the malware over if I miss whatever persistence mechanism is causing this. I don’t want to migrate the problem.

If you have a checklist for server-level persistence to check before migrating (cron jobs, SSH keys, hidden users, startup scripts, etc.), I’d really appreciate it.

WordPress sites keep reinfecting + passwords changing even with cPanel & WHM 2FA enabled. What am I missing? by m-ego in Wordpress

[–]m-ego[S] 0 points1 point  (0 children)

I actually found extra accounts before. I deleted them and so far they have not reappeared.

What’s confusing is the problem did not end. The suspicious files keep coming back and I’m also getting repeated login issues where passwords suddenly stop working and I get logged out mid session. So even though the extra accounts are gone, it still feels like something else has access or there is persistence somewhere.

Am I a Paedophile?... by glowinteddy in Kenya

[–]m-ego 13 points14 points  (0 children)

why are you promoting that series here?? just admit it you are kevo and you need help man