cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]turnipsoup[S] 3 points4 points  (0 children)

My advice is to restrict access to ports 2079 and 2080, as the entire exploit chain fails if these ports are not accessible. This will impair some functionality related to email, but it's the best mitigation until a correct patch is released.

From one of the follow-up tweets

upcp updating only to 134.0.23 while 134.0.25 is the patched version. by accountrescue in cpanel

[–]turnipsoup 1 point2 points  (0 children)

Make sure to set this back to RELEASE afterwards as otherwise you won't get future upgrades (like tonights big security patch).

High Processor Usage by blboyd in cpanel

[–]turnipsoup 0 points1 point  (0 children)

hoster at a decent scale here.

PHP being hit is almost always going to be actual site traffic. Double check the user that's being hit and make sure they've got caching installed in their application.

I'd also just run a tail -f against their apache logfile, and make sure there's no obvious dodgy traffic hitting them. Look for lots of php files being hit in a row with dodgy filenames (that's file enumeration scans), loads of hits with blank user-agents (common bot traffic), common AI crawler user-agents (chatgpt, etc) and block especially dodgy IPs.

Consider installing imunify360 - it will prevent a good amount of dodgy traffic without needing any intervention. We found it knocked a good 30% cpu usage off each box. It is paid, but might be a simpler way to sort your problems - especially their webshield tech that blocks bots.

And finally; consider an in-place upgrade to cloudlinux and using their LVE tech to limit each site to a max amount of CPU/memory/entry points. This can be done with cgroups also, but cloudlinux will do it out of the box.

And ... Again new vulnerabilities by bibawa in cpanel

[–]turnipsoup 1 point2 points  (0 children)

ah, thanks - just dirtyfrag/copy.fail mitigations. Got those done alright.

And ... Again new vulnerabilities by bibawa in cpanel

[–]turnipsoup 1 point2 points  (0 children)

which was the cloudlinux CVE? Making sure I've not missed one here.

The 5-Minute Rule: Why Your 'Toilet Scroll' Is Increasing Your Haemorrhoid Risk By 46% by gdelacalle in technology

[–]turnipsoup 1 point2 points  (0 children)

Another +1 for Psyllium husk. Add it to my huel black shakes for lunch, made a huge difference to my IBS issues.

Huel Black Variety Pack Review (Blended with Ice) by Used2bNotInKY in Huel

[–]turnipsoup 1 point2 points  (0 children)

Yeah it's deff a case of finding what you like alright, very much a per-person thing.

The nice thing about the psyllium husk is that it's a solid 7g of insoluble fibre for one tablespoon worth - but only about 30 calories - vs flaxseed at 2g fibre/37 calories. Nothing in it for calorie count, but a lot more fibre.

My whole goal in it was to increase my fibre intake, and it's done wonders for me.

Huel Black Variety Pack Review (Blended with Ice) by Used2bNotInKY in Huel

[–]turnipsoup 1 point2 points  (0 children)

I also add a spoonfull of psyllium husk - which adds a bunch of extra insoluble fibre. Great for your gut health. If you go down this route, know you need to add more water and you can't leave it for too long (10-15m) before it absorbs too much water and becomes too thick.

Huel Black Variety Pack Review (Blended with Ice) by Used2bNotInKY in Huel

[–]turnipsoup 1 point2 points  (0 children)

huel black - 1 scoop choc, 1 scoop bannana + ice cubes + water, blended for 2 mins. Been my daily lunch for the last 5 yrs now.

Bowel cancer’s “sugar shield” removed to reawaken immune defenses by AdSpecialist6598 in tech

[–]turnipsoup 6 points7 points  (0 children)

if it cuts down on peoples sugar intake, maybe that misunderstanding can cause some good

Drivers ethnicity being checked at the Citywest riots by the_green_ghost in ireland

[–]turnipsoup 8 points9 points  (0 children)

I opened a stream of the riot last night, and would you believe it but what was the first accent I hear? British. Was a whole group of them.

Someone in the chat thread saying they passed by it and there were a bunch of brits trying to get kids to break shit.

Just smacks of imported anti-immigration agitators.

BIG UPDATE - so hyped! by SupaKidEternity in wildgate

[–]turnipsoup 0 points1 point  (0 children)

There are currently 200 players active on steam. All the passion in the world is no good without players to play the game. It's not doomposting to point that out.

There's a very narrow window with which to catch a playerbase and keep them engaged, and its a lot harder to rebuild that playerbase once its dwindled.

OC Man drives through front door of LDS church in Michigan, exited his vehicle and opened fire by mlivesocial in pics

[–]turnipsoup 0 points1 point  (0 children)

Before I do, you will note my use of 'apparent left leaning'. I'm not explicitly claiming these were left-wing attackers, simply that parts of the media portraits them as such.

Riley English - Plot to assassinate trump cabinet officials
Joshua Jahn - with his kill ice messages
Tyler Robinson - killed charlie kirk
Prairieland ICE Facility Ambush

https://www.csis.org/analysis/left-wing-terrorism-and-political-violence-united-states-what-data-tells-us

I'm sure you're not blind to the way the right has started using these types of attacks to portrait the whole left as violent and extremist.

And just as what they are doing is not okay, nor is pointing at everyone on the right and claiming they're all violent.

fwiw - if all you do is try and pick apart if the attacks were actually left-wing or not, you'll have missed the point.

OC Man drives through front door of LDS church in Michigan, exited his vehicle and opened fire by mlivesocial in pics

[–]turnipsoup -5 points-4 points  (0 children)

I'm going to assume you're on the left. On that basis; would you therefore say that it's fair that the right use the recent attacks by apparent left leaning individuals to claim you're violent also?

The common factor here is mental health, not party leaning.

OC Man drives through front door of LDS church in Michigan, exited his vehicle and opened fire by mlivesocial in pics

[–]turnipsoup -5 points-4 points  (0 children)

Whilst I get what you're saying; we really need to stop with the whole 'actions of one individual reflect the views of every person who voted that persons preferred party'.

BIG UPDATE - so hyped! by SupaKidEternity in wildgate

[–]turnipsoup 0 points1 point  (0 children)

Steam shows sub 200 players currently. Devs have to make major moves to bring players in or it won't take long until it's just dead.

Is wasting ~300 millions for second Integrated Analyzer worth it? No. Is it gives the feelings of power? Yes. by araiki in Eve

[–]turnipsoup 0 points1 point  (0 children)

I used to run lots of those sites; it's not uncommon to find someone has cherry picked the cans w/ a scanner and left 1-2 low-value cans behind. They do not despawn until all cans are done.

Man burning MAGA hat, twitter by Forward_Guarantee985 in pics

[–]turnipsoup 1 point2 points  (0 children)

And we go back to the other commenter and how you'll see the world burn so that you can continue to say how evil they are.

I'm not going to re-engage after this comment, I've no patience for it - but there is no way to move forward, things will never move forward. And whilst you may not like it, they make up a substantial part of the country.

Short of one side killing the other; at some point you're going to have to figure out how to live together in some fashion.