Deceiving cPanel ‘Account Suspended’ page serves exploits

  • 26 February 2015
  • 0 replies
  • 2 views

Userlevel 7
Badge +54
February 26, 2015 | BY Jérôme Segura
 
cPanel is one of the most popular web hosting control panels out there. It allows administrators to manage their website(s) using a graphical front end, perform maintenance and review important logs among other things.
cPanel also has a user interface for CGI (short for Common Gateway Interface) typically used to run scripts and generate dynamic content.
One such script populates a fairly well-known (and somewhat dreaded) page known as the “Account Suspended” page:
 


 
Visitors to a site are redirected to this screen for one of many reasons ranging from the site owner’s failure to pay for his hosting, violating the Terms and Conditions, or perhaps exceeding their allocated bandwidth.
The script that loads this page is located here:
/usr/local/cpanel/cgi-sys/suspendedpage.cgiThe page itself is made of HTML code, and can be edited by an administrator, often via a Web Host Manager (WHM).
Many sites that were once used to distribute malware and have been suspended will sport that kind of page. One would assume that the site would now be harmless, since the hosting provider has already taken action.
 
Full Article

0 replies

Be the first to reply!

Reply