Cpanel Boycott - Can you really trust your cpanel host?

Status
Not open for further replies.

skraps

New member
Cpanel went on for 2 years with a remote root exploit in exim 4.69(released: 12-27-2007 11:29 AM) that allowed attackers to gain complete control over the servers. Hosts that use cpanel, Hostgator.com and many others. Unlike qmail(qmail.org) that has a track record of zero security flaws. Along with tinydns that has had one security flaw but not a serious one. It only allowed attackers to crash the daemon then it needed to be restarted.

Why is this so serious? Imagine how many E-Commerce sites are built on top of that platform. If you run a cpanel server inside yhour network that has access to the outside world. You could now have crackers using that cpanel box as a base to compromise and attack other computers on the network from. The possiblitiy that a massive DDOS attack was on it's way the 2012 of the internet? Your whole datacenter turns on you.

("200,000 "web site hosting vendors", all cPanel-based, yet uniquely labeled")

("Here's where: more than 98% of these 200,000+ different web hosting brand names in the world will offer you exactly the same cPanel Control Panel and platform, labeled in a different way, with the same price tags!")

Information taken from - www.resellerhostingclue.com

Any site in the past 3 years that has received your personal information , name , address, telephone, and credit card numbers has more than likely been compromised and "black hat hackers"(the evil doers) have your information at their disposal.

A lot of shared servers. Like hostgator.com , and many more here -

Google Search

This is how easy it was for a attacker to gain complete control over these hosts.


Also cpanel prefers performance over security. None of these services include chkrootkit, rkhunter, obscure installs of tripwire. None of the services use chroot for the daemons. http://en.wikipedia.org/wiki/Chroot

10 other web hosting panel alternatives that are free

10 free cpanel alternatives

ISPConfig is a great alternative that is feature rich and even includes multiple server monitoring and virtual machine monitoring/control. This is put together by the people at howtoforge.com , the only thing they ask is if you can, buy a subcription for 6-USD to their site. Where they give the same support and quality tutorials to everyone for free anyways! That is nothing more genuine than that.

Basically every host I have talked to only say they patched their servers. None of them reinstalled the base then reinstalled cpanel. Knowing Hostgator there is no tripwire and most hosting companies would not take the time to ensure the safety of the data. Mainly because that would cost them money and resources. Moving the accounts, going through all the code of the websites looking for malware and web based shells. Last updates made to the most popular root kit checking software on the market. AVG also has a Linux virus scanner but I am unsure of its capabilities. The windows version of AVG is rock solid. ( http://free.avg.com )

To ensure integrity/safety of the data is by reinstalling the base and then cpanel or a alternative, finally moving the accounts back to the servers is the only solution. This is because chkrootkit and rkhunter only have been trained to find known root kits in common places. This does not include back doors implanted into obscure places. This does not include checking the kernel for mods that enable a attacker to compromise the host.

Last updates to these pieces of software -

2009-30-9 rkhunter

2010-11-17 - chkrootkit



Responses from a couple cpanel hosts:


Hostgators Responses:

Live Chat Powered By Live chat powered by GatorChat Rate And Exit Rate / Exit

Your Chat ID is: 5126762. Your initial question is:: My Domain Name is:"techjunkies.com"

Welcome to GatorChat!

You are being connected to a representative in our Technical Support department right now.

For immediate answers to your questions, check out our knowledge base and video tutorials at http://support.hostgator.com/.

(2:10:55pm)SystemCustomer has entered chat and is waiting for an agent.

(2:13:15pm)Leslie A.Welcome to HostGator LiveChat. My name is Leslie. I'd be glad to assist you today with your inquiry.

(2:13:17pm)Leslie A.Hello, John!

(2:13:19pm)Leslie A.How may I assist you today?

(2:13:30pm)John WalkerWhats this ?https://www.facebook.com/pages/Boycott-Cpanel/324347710917547

(2:13:38pm)John WalkerI found it on facebook

(2:15:46pm)Leslie A.After glancing over the article, I can see that they mention us, but I have no knowledge of this "exploit", and I can assure you we have full security on all our servers.

(2:16:01pm)Leslie A.This page was made without our knowledge, and I cannot comment directly on the subject.

(2:16:23pm)John WalkerThank you. Good bye.
Your Chat ID is: 5126817. Your initial question is:: My Domain Name is:"Mashable.com"

Welcome to GatorChat!

You are being connected to a representative in our Billing department right now.

For immediate answers to your questions, check out our knowledge base and video tutorials at http://support.hostgator.com/.

(2:21:29pm)SystemCustomer has entered chat and is waiting for an agent.

(2:23:26pm)Grant C.Welcome to HostGator Live Chat. My name is Grant, I would be more than happy to assist you today.

(2:23:37pm)John MayersWhats this? https://www.facebook.com/pages/Boycott-Cpanel/324347710917547

(2:24:11pm)Grant C.Looks like a facebook page for people who dont like cPanel.

(2:24:48pm)John MayersIt says that all cpanel server where compromised by a security flaw that was in the wild for 2 years before being discovered

(2:24:54pm)John Mayersservers*

(2:25:23pm)John MayersDi you guys patch the servers?

(2:25:38pm)Grant C.Oh, yes, that was a while ago, we took care of that, John.

(2:25:53pm)John MayersSo all the server where just patched?

(2:26:13pm)Grant C.Yes, we ran the cPanel patch over a month ago.

(2:26:34pm)John MayersThanks that makes me feel so much better about the whole issue

(2:26:59pm)Grant C.I am happy to hear it, John.

(2:27:00pm)Grant C.Is there anything else I can clear up for you/do for you to bring resolution to this issue?

(2:27:13pm)John MayersNope I was just concerned.

Routehosts Response:
Hi,
Thanks for the update. We've already installed necessary security patches to avoid such vulnerabilities.

Regards
Support Team
----------------------------------------------
Ticket ID: #546697
Subject: Exim 4.69 major problem
Status: Answered
Ticket URL: http://secure.routhost.com/viewticket.php?tid=546697&c=BahshgvT
----------------------------------------------

Hurdles pushing this information to the public -
Grub Help mailing list -

Greg implicitly states he knows a person that works at one of the two companies. Then proceeds to calls this a scam and me a fraud. Greg and Mark then decided to move the argument off list and proceed to call me a liar after moving the private message he sent me that was vulgar to the public list saying I am a fraud/liar because I changed the reply to the group and not directly to them. I admit I'm not the best but I am not scamming anyone about these issues.

Emails of the conversations and these are also available via the mailing list archives publicly search able on google.

email1

email2

email3

Web Hosting Talk -

Then on web hosting talk I started a thread called "Boycott Cpanel". That was shutdown after about a hour after mentioning the connections between the site and having hostgator employees as their own content curators. I also mentioned the connections between cpanel and hostgator. I even went as far as I posted a message and link back to the facebook boycott page and my account was then banned. Apparently touching on the sensitive areas of their operations they try to keep quite upsets them.

Webhosting talk thread

PDF

To hosting companies -

By using cpanel, you are supporting your competition. Hostgator and cpanel routinely trade employees and small amount of evidence can be found on likedin. You can see from the profiles on linkedin. If your a good admin at cpanel you get sent to hostgator. If your a good programmer or one of the trusted higher ups with a impeccable background you get sent to cpanel.

Nate Custard
PDF
Linkedin

Josh B. -

PDF
Linkedin

Chris B. -

PDF copy - PDF
Linkedin - Linkedin
 
Security flaws are not uncommon in any piece of software, so I am not sure why this is such a big deal.

Even the best run companies get hacked, information gets lost daily. All you can do is do your best, stay on top of server security and when something goes wrong - fix it quickly.

And to answer your question "Can you really trust your cpanel host?" - Yes, I can and I do.

PS: Most of your links don't even work.
 
the links that got turned into asterix are really supposed to be a tiny url. @JFSG of course you would say that , you sell cpanel. This isn't a personal attack on HG. This is a attack on ever system that ran cPanel before december 2010 and it just so happens to be 75%+ of hostgators shared and seo servers.
 
the links that got turned into asterix are really supposed to be a tiny url. @JFSG of course you would say that , you sell cpanel. This isn't a personal attack on HG. This is a attack on ever system that ran cPanel before december 2010 and it just so happens to be 75%+ of hostgators shared and seo servers.


what are you on, have they let you out of the asylum. you are on about an exploit from 2007 (5 yrs ago) and then systems before Dec. 2010 (12 months ago)
i have had cpanel systems since i started in the hosting business in 1999 and have never had any problems.
 
So you got banned at WHT and expect better here? Your crusade against Hostgator and cPanel is failing miserably.
 
what are you on, have they let you out of the asylum. you are on about an exploit from 2007 (5 yrs ago) and then systems before Dec. 2010 (12 months ago)
i have had cpanel systems since i started in the hosting business in 1999 and have never had any problems.

No it was a exploit discovered in dec 2010, that was around since 2007 .

*Insane Asylum Escape*
 
So you got banned at WHT and expect better here? Your crusade against Hostgator and cPanel is failing miserably.

This isn't a direct attack on cpanel or hostgator, this is more or less a warning.
 
hosthater, yeah... duh... hater towards the hosts. Honestly I'm really not biased at all. I'm still trying to find something good on rackspace. Godaddy, I just don't have enough ammunition yet. Though some funny office picks. Godaddy is so cheap they are moving their offices out in the parking lot? Check google maps, you can see them arranging the desks out there, lol
 
No it was a exploit discovered in dec 2010, that was around since 2007

So?? :uhh:

It was fixed when it was discovered.

I really am failing to see the point of your campaign on a piece of 2-year old news.

This isn't a direct attack on cpanel or hostgator, this is more or less a warning.

A warning of something that happened 2 years ago?
 
No it was a exploit discovered in dec 2010, that was around since 2007 .

such a big exploit that effected many cpanel users but not a mention on the cpanel forum, which if cpanel users were effected by this i am sure it would have made the cpanel forum.

i just wonder why you have been banned from many forums when you wrote this same post on them.
 
Last edited:
Well webhosting talk banned me because I made the connection between their content curators that are on hostgators payroll. Evidence on linkedin.

The next article is going to be better. Titled - "It takes thrice to rule the world"
 
Well webhosting talk banned me because I made the connection between their content curators that are on hostgators payroll. Evidence on linkedin.

The next article is going to be better. Titled - "It takes thrice to rule the world"

so what about it, so an admin on WHT works got hostgator, how do you think these forums are set up, with contributions etc. from major webhosting companies etc.

if you abuse any forum staff etc. then you will be banned from the forums.

all i see is that you are 100% trouble maker
 
Artashes: this only ended a year ago, it started 3 years ago. So for 2 years thousands if not 1 million plus web servers have more than likely been rootkitted or had there kernels modded. This is huge. It's part of something so much bigger that apparently everyone wants to be part of. I can't go into right at the moment. This is pure evil, and its not just a hostgator/cpanel thing. There are other companies involved also.

Need to look into some of the recent discoveries from NC State University. That paper will be out soon.

do you not think if this was the case users would of complained and made comments on the cpanel forum (http://forums.cpanel.net/forum.php) but as no mention this is just you making trouble.

i bet you are one of thoise who were kicked off hostgater hosting and just now causing trouble
 
Last edited:
Skraps, there has always been restrictions to freedom of speech and rightfully so. A free world?? Are you living on the same planet as the rest of us? J/K, Skraps. Seriously, how does the concept of a free world play into any of this? And I agree with Terry here. How would you prefer web hosting forums be administered? Shouldn't it be by those who are actually in the industry?
 
Last edited:
Status
Not open for further replies.
Back
Top