logoalt Hacker News

CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

109 pointsby ggallasyesterday at 5:06 PM59 commentsview on HN

Comments

zuzululuyesterday at 5:57 PM

Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously

Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain

show 3 replies
anonzzziesyesterday at 5:55 PM

CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.

show 3 replies
0xbadcafebeetoday at 12:38 AM

44,000 servers compromised? Sounds like somebody could've used a software building code

eagerpaceyesterday at 7:44 PM

Wow, similar sentiments about this being a throw back. I’d rather roll my own almost everything these days, may not be as good, but certainly won’t be targeted exploited broadly.

show 1 reply
josuyesterday at 9:57 PM

So CPanel's security is just as bad as their UI, who would have thought?

operatingthetanyesterday at 5:48 PM

People are still using cpanel?

show 4 replies
zb3yesterday at 8:47 PM

"AI safeguards" are not working I guess.. or maybe they're only working against those who'd like to secure their software.. good job Anthropic + OpenAI!

rickdgyesterday at 8:11 PM

Friendly reminder that there aren't that many ways for a normie to create their own (sub)domain with TLS and an email in under five minutes. That's cPanel for ya.

show 2 replies