Community forum to discuss cxs.
If you believe that there is a problem with your cxs installation and want support then, as a paid product, you should use the helpdesk after having consulted the documentation.
I am getting a lot of exploits undetected by CXS on normal settings.
I have my sever set to bayes low for report & quarantine and am getting these quarantined. I am protected so aren't worried for me, but in the course of my work I am seeing a lot of newly exploited wordpress sites and no one has yet proved what exploit is allowing the sites to be used for distributing malware
I know they are...
I am a server administrator and use DirectAdmin as a server manage solution for my clients and I am very interested about your ConfigServer eXploit Scanner (cxs) product, it looks very promise and probably will enchance security but... Is it possible to install and use CXS on a DirectAdmin server or if not yet are you planning to port this...
How can I tell cxs to scan a list of files? It seems to accept only a single resource (file name or directory) on the command line.
I've tried entering more than one on the command line, but cxs only scans the first resource specified.
I've tried using the --xtra option on a file with a few file:/full/path/to/file entries, but cxs seems to ignore them completely and only scan the single file I...
I am seeing the error below when I go to ConfigServer eXploit Scanner in WHM:
Error trying to talk to ClamAV socket : Connection refused
You must install ClamAV (Clamavconnector on cPanel) or ensure clamd is running to use this product correctly
If the clamd socket is not automatically detected, and to clear this message, you must set clamdsock=/path/to/socket in /etc/cxs/cxs.defaults to the...
I'm hoping someone can help me determine what is being reported here... I have a default configuration of CXS, that was installed by configserver as part of the cPanel Server Service.
Scanning web upload script file...
Time : Mon Apr 20 06:13:19 2015 -0400
Web referer URL :
Local IP : 111.222.333.444
Web upload script user : nobody (99)
Web upload script owner: legitusername (600)
Web...
I have read your advice regarding using the ignore file - but I work at a UK host, and we have a lot of CXS licenses, on servers which host thousands of Magento sites - many of whom use Extendware - nearly all of this company addons are obfuscated and are flagged up:
Known exploit = [PHP Obfuscation Exploit ]
While local ignores are fine for less common FPs, it would be good if you had a...
Sep 15 12:40:38 www cxswatch : WARNING: '/home/user/public_html/error_log' scanned 6 times in the last 30 seconds, you might want to ignore this resource
Any ideas what might cause this, or whether ignoring:
hfile:/public_html/error_log
is advisable for all? (Does cxs scan the log file?)
I copied the example ignore file and renamed it cxs.ignore
and have added a rule in the file :
hdir:/public_html/wp-content/wflogs
but still in email i am getting this warning :
Aug 26 10:03:51 home cxswatch : WARNING: '/home/******/public_html/wp-content/wflogs/config.php' scanned 6 times in the last 30 seconds, you might want to ignore this resource
Aug 26 10:03:51 home cxswatch : Ignoring...
CXSwatch seems to have stopped sending emails across a number of servers in the last few days, I want to do some testing - is there a test exploit script that will trigger it?
I'm curious as to why CXS flags as outdated the current version of Joomla, and states that Joomla 3.6 is the current version. Joomla 3.6 is still in Release Candidate stage.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum