CyberPanel Community

Cyberpanel hacked

ho
hostbdfree #1

You are receiving this email because LeakIX’s NetworkGuardian has found a critical issue on your network.
If you are an hosting company, your cooperation on contacting the affected customer would be welcome and could help protect your network from abuse.
Source
https://209.209.40.227:8090
Ip
209.209.40.227

Discovered
28 Oct 24 13:09 UTC

Plugin
CyberPanelPlugin

Reported to
admin@cloudclusters.io

Issue description

The following CyberPanel administration interface is publicly accessible and looks out-dated :

It is critical to update to a safe version as soon as possible since multiple CVEs allow remote attackers to achieve RCE (Remote code execution) on the firewall.
Those vulnerabilities are currently used in ransomware campaign and could damage your network.

Make sure you are running branch 2.3.7.
Reference:

Summary:
Found vulnerable CyberPanel instance
Affected by EXT-2024-003
Need help, have questions or are we hitting the wrong email address? Contact us at support@leakix.net, we’d love to help.

Cathy
Support Department

24 replies
SD
SaJeTek Developer #2

Damn, at least I now know where the exploits came from.
Does not help the cleanup process though

RA
Rabia Abu Hanna #3

What is the Solution guys? Can we still keep the Files or need to reinstall everything?

ma
maxwell #4

The solution is to update the cyberpanel, but the blog post says that other vulnerabilities have been detected.

RA
Rabia Abu Hanna #5

Which version to use?
2.3.7 or higher?

Gi
Giannis #6

2.3.8 the latest

di
dipanshi #7

my websites are hacked unknown files are showing in public_html folder these files have been uploaded from

Ал
Александр #8

L0CK3D I have all the files and what am I supposed to do with it? The developers were warned in advance and they didn’t say anything

tr
trifo13 #10

I am in the same boat :frowning:

I have a month-old backup of the sites, not a huge deal, but I am very, very disappointed with how the developers handled this. They should have warned us :frowning:

Ал
Александр #11

it’s only for the simplest kind of encryption.

Ал
Александр #12

I’ve suffered thousands of dollars in losses due to their actions.

2F
2FED #13

I am in the same boat too. My site is down and i have backup.
But after restoring backup i can’t acces to my site. Getting 500 error. What can be wrong? Restarted CyberPanel, but nothing happend. Still 500 error. Can anybody help?

Ал
Александр #14

поставь fastpanel и живи счастливо

2F
2FED #15

Для начала надо бы из бэкапов восстановиться.

Ал
Александр #16

Хорошо, когда они есть, мне пришлось заплатить за этот опыт

2F
2FED #17

Видел твой пост. Сочувствую. Только не понимаю как ты заплатил 1.2к зелени если они просят 1 биток.

Ал
Александр #18

у меня просили 1200 долларов

Ал
Александр #19

там работало 3 хакерские группы

Ro
Roman #21

у меня норм после обновы

Ro
Roman #22

я думаю, что даже больше

2F
2FED #23

Thanks. I will try to see logs. I’m not using WP.

Ст
Станислав #24

Какие расширения у тебя были ? . locked или . encryp?

Sign in to reply