Community forum to discuss cxs.
If you believe that there is a problem with your cxs installation and want support then, as a paid product, you should use the helpdesk after having consulted the documentation.
I get inundated with hacker activity, mainly exploiting Wordpress to install files which CSXS deletes or quarantines but nothing stops the same hackers on the same IP addresses from attacking multiple WP installs.
I don't know of a way to deal with the issue other than to manually block all of the IP addresses. Maybe blocking the IP addresses does no good as it seems I am chasing my tail. No...
Actually we would like to extend the CXS to our 10 other servers , however we would like to have some clarifications please :
1 - We run only CXS watch deamon with CLAMAV , this will be enough to detect and protect against mass defacement perl scripts ?
2 - In CXS watch deamon logs i never see that CXS find something suspect ? should i mandatory create QUARANTINE or there is one by...
I find cxs very usefful on our Cpanel servers, and wish to use it on non-cpanel servers, to ensure their security.
I see that Cpanel is required, but i dont know if is viable use it (on limited way, or just only a few features) on non-cpanel server, or its not possible (and never be because...) use cxs on non Cpanel server.
Only i need is scan for files and daemon. Not need of interface or...
we're getting a lot of alerts for exploit P1410 but the affected files seem to be a simple archive script included in a lot of apps like coppermine, joomla extensions, CMS Made Simple and so on. The apparently bad file is even included in official sources of the named products. I don't know if maybe some malware used partially the same code as the legitimate script and now all are...
I understand about the false-positives (when the file doesn't exist), but I get a lot of e-mails having to do with viruses or fingerprints referring to files like:
or
These files get quarantined, but does that mean these wordpress files are exploitable and hackers are actually uploading files?
Or does this mean that someone did an apache POST and the...
I would like to know if by default cxs will run server-wide scan automatically (either by cronjob or other way?)
If yes, how to disable it?
Also I would like to know the command to scan one home dir only. Let say I want to scan /home/test/
What command I should run?
#!/bin/sh
#
# This file is part of the phpseclib project.
#
# (c) Andreas Fischer
#
# For the full copyright and license information, please view the LICENSE
# file that was distributed with this source code.
#
set -e
set -x
After enabling IP reputation integration, I had multiple occasions of cpanel monitoriog reporting lfd failures and subsequent restarts on 2 servers. From lfd.log I was able to determine that the URI::Escape module was not installed. I manually installed that and thought the lfd stops and starts would be corrected. Alas I am now seeing FASTART errors that seem to coincide with the failures. I...
I have the following report, is this a real or a false positive?
Thanks
/daveb
Scanning web upload script file...
Time : Tue, 19 Sep 2017 08:42:25 +1000
Web referer URL :
Local IP : 103.237.108.162
Web upload script user : nobody (99)
Web upload script owner: ()
Web upload script path : /home/purecalm/public_html/wp-content
Web upload script URL :...
Hello,
i have the latest version of CXS in cpanel.
Also i have some extra clamav rules from Atomicorp.
When i scan with clamscan -r -i /home/path/public_html
i can find some virus, for example Atomicorp.PHP.Malware.19.UNOFFICIAL FOUND
However when i scan with cxs, even if i enable all options for virus i find nothing.
For example:
/usr/sbin/cxs --report /var/log/cxs.scan --logfile...
I get people trolling I guess looking for scripts on the server to try to exploit.
I did change the username and domain name.
What I am wondering is how can I block and/or ban the IP address of the person after xx amount of hits?!?!
Scanning web upload script file...
Time : Mon, 4 Sep 2017 11:12:56 -0700
Web referer URL :
Local IP : 123.123.123.123
Web upload script user : nobody (99)
Web...
The root email address is receiving cxs scan emails fine which is excellent. How can one configured CXS to send an email to the script owner's email address as well notifying of the quarantined file?
CXS was installed without any problems. CPanel den ConfigServer Clicking Exploit Scanner gives an error. We have updated Cpanel. I restarted the services and it did not work. I'm waiting for your help.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum