{"id":7424,"date":"2022-02-01T18:54:31","date_gmt":"2022-02-01T18:54:31","guid":{"rendered":"https:\/\/www.hostingseekers.com\/blog\/?p=7424"},"modified":"2025-03-06T11:05:20","modified_gmt":"2025-03-06T11:05:20","slug":"linux-server-faced-rce-attacks","status":"publish","type":"post","link":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/","title":{"rendered":"Linux Server Faced RCE Attacks Due to Severe Bugs in CentOS"},"content":{"rendered":"<blockquote><p>Extensive research recently found two severe security malfunctions (CVE-2021-45467) in the <strong>CentOS Web Panel<\/strong>. These were used as a vital part of an attack chain on the affected host, in order to gain the pre-authenticated Remote Code Execution (RCE).<\/p><\/blockquote>\n<p>CentOS Web Panel, which is now known as Control Web Panel, is a free and open-source Linux Control Panel that is used to set up the hosting settings.<\/p>\n<hr \/>\n<h2>Tracking Bugs (CVE-2021-45467)<\/h2>\n<p>After tracking the bugs (CVE-2021-45467), it is found that the issue was a case of file inclusion vulnerability. This issue occurs when the web application is tricked into exposing or running arbitrary files on the webserver.<\/p>\n<p>Paulos Yibelo of Octagon Networks identified these issues and then he stated that the problem usually occurs when two applications with authenticated PHP pages, like \u2013 \u201c\/user\/login.php\u201d and \u201c\/user\/index.php\u201d \u2013 fails to fully validate a path to a script file.<\/p>\n<p>This simply means, it becomes an easy job for attackers, as they only have to change the include statement. That\u2019s it. Malfunctioning in the include statement makes them easy to incorporate the content of one PHP file into another PHP file, which ultimately injects the malfunction code from a remote resource. This way, they easily gain code execution.<\/p>\n<hr \/>\n<h3>Preventive Measures<\/h3>\n<p>The program already had tight protections to signal any attempts conducted to switch to a parent directory (denoted by \u201c..\u201d) as a hacking attempt. But, surprisingly, it did not stop the PHP interpret from allowing a specially generated text ( .\u201d$00\u201d. )to enter the code by smoothly bypassing the application.<\/p>\n<p>It allowed arbitrary file write vulnerability (CVE-2021-45467) as well as allowed bad actors to acquire access to the complete remote code execution on the server.<\/p>\n<p>Now, CWP has resolved the issue and released the fixes earlier this month.<\/p>\n<hr \/>\n<h4 id=\"047b\" class=\"ht hu dt hv b hw hx hy hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq dl eq\"><em>If you enjoyed reading this news, you are surely going to cherish these too \u2013<\/em><\/h4>\n<ul>\n<li>\n<p class=\"custom_title\"><a href=\"https:\/\/www.hostingseekers.com\/blog\/google-enters-blockchain-space\/\"><em><strong>Google Sets Up Digital Assets Team To Ramp Up Blockchain Efforts<\/strong><\/em><\/a><\/p>\n<\/li>\n<li><a href=\"https:\/\/www.hostingseekers.com\/blog\/google-acquired-siemplify\/\"><em><strong>Google Acquired Cybersecurity Specialist Siemplify For $500M<\/strong><\/em><\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Extensive research recently found two severe security malfunctions (CVE-2021-45467) in the CentOS Web Panel. These were used as a vital&hellip; <a class=\"more-link\" href=\"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/\">Continue reading <span class=\"screen-reader-text\">Linux Server Faced RCE Attacks Due to Severe Bugs in CentOS<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":6395,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[238],"tags":[],"class_list":["post-7424","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Linux Server Faced RCE Attacks | HostingSeekers<\/title>\n<meta name=\"description\" content=\"Linux Server Was Attacked by RCE due to Severe Bugs (CVE-2021-45467) in CentOS Web Panel. All you need to know about how the issue was identified and solved.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Linux Server Faced RCE Attacks | HostingSeekers\" \/>\n<meta property=\"og:description\" content=\"Linux Server Was Attacked by RCE due to Severe Bugs (CVE-2021-45467) in CentOS Web Panel. All you need to know about how the issue was identified and solved.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Hostingseekers\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/hostingseekers\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-01T18:54:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-06T11:05:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"manvinder Singh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Hostingseekers1\" \/>\n<meta name=\"twitter:site\" content=\"@Hostingseekers1\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"manvinder Singh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Linux Server Faced RCE Attacks | HostingSeekers","description":"Linux Server Was Attacked by RCE due to Severe Bugs (CVE-2021-45467) in CentOS Web Panel. All you need to know about how the issue was identified and solved.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Linux Server Faced RCE Attacks | HostingSeekers","og_description":"Linux Server Was Attacked by RCE due to Severe Bugs (CVE-2021-45467) in CentOS Web Panel. All you need to know about how the issue was identified and solved.","og_url":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/","og_site_name":"Hostingseekers","article_publisher":"https:\/\/www.facebook.com\/hostingseekers","article_published_time":"2022-02-01T18:54:31+00:00","article_modified_time":"2025-03-06T11:05:20+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg","type":"image\/jpeg"}],"author":"manvinder Singh","twitter_card":"summary_large_image","twitter_creator":"@Hostingseekers1","twitter_site":"@Hostingseekers1","twitter_misc":{"Written by":"manvinder Singh","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#article","isPartOf":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/"},"author":{"name":"manvinder Singh","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/person\/76bc9258cab3c5bfe0237d3e290b13ea"},"headline":"Linux Server Faced RCE Attacks Due to Severe Bugs in CentOS","datePublished":"2022-02-01T18:54:31+00:00","dateModified":"2025-03-06T11:05:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/"},"wordCount":341,"commentCount":0,"publisher":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg","articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#respond"]}],"copyrightYear":"2022","copyrightHolder":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/","url":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/","name":"Linux Server Faced RCE Attacks | HostingSeekers","isPartOf":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg","datePublished":"2022-02-01T18:54:31+00:00","dateModified":"2025-03-06T11:05:20+00:00","description":"Linux Server Was Attacked by RCE due to Severe Bugs (CVE-2021-45467) in CentOS Web Panel. All you need to know about how the issue was identified and solved.","breadcrumb":{"@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#primaryimage","url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg","contentUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2022\/02\/Linux.jpg","width":1200,"height":675,"caption":"RCE Attacks Identified On Linux Server"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hostingseekers.com\/blog\/linux-server-faced-rce-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hostingseekers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Linux Server Faced RCE Attacks Due to Severe Bugs in CentOS"}]},{"@type":"WebSite","@id":"https:\/\/www.hostingseekers.com\/blog\/#website","url":"https:\/\/www.hostingseekers.com\/blog\/","name":"Hostingseekers","description":"Hostingseekers","publisher":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hostingseekers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hostingseekers.com\/blog\/#organization","name":"HostingSeekers Pvt. Ltd.","url":"https:\/\/www.hostingseekers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2025\/04\/Hosting-Seekers-Logo.png","contentUrl":"https:\/\/www.hostingseekers.com\/blog\/wp-content\/uploads\/2025\/04\/Hosting-Seekers-Logo.png","width":451,"height":520,"caption":"HostingSeekers Pvt. Ltd."},"image":{"@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/hostingseekers","https:\/\/x.com\/Hostingseekers1","https:\/\/www.linkedin.com\/company\/hostingseekers\/","https:\/\/www.instagram.com\/hostingseekers\/"]},{"@type":"Person","@id":"https:\/\/www.hostingseekers.com\/blog\/#\/schema\/person\/76bc9258cab3c5bfe0237d3e290b13ea","name":"manvinder Singh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4373df1ab2b4f1e40b27df8913e40d494a7fd38d128e0ac30e9f7406a4f96e91?s=96&d=mm&r=g","caption":"manvinder Singh"},"description":"Manvinder Singh is the Founder and CEO of HostingSeekers, an award-winning go-to-directory for all things hosting. Our team conducts extensive research to filter the top solution providers, enabling visitors to effortlessly pick the one that perfectly suits their needs. We are one of the fastest growing web directories, with 500+ global companies currently listed on our platform.","sameAs":["https:\/\/www.hostingseekers.com","https:\/\/www.linkedin.com\/in\/manvinder-singh\/"],"url":"https:\/\/www.hostingseekers.com\/blog\/author\/seodeveloper\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/7424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/comments?post=7424"}],"version-history":[{"count":2,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/7424\/revisions"}],"predecessor-version":[{"id":35438,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/posts\/7424\/revisions\/35438"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/media\/6395"}],"wp:attachment":[{"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/media?parent=7424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/categories?post=7424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostingseekers.com\/blog\/wp-json\/wp\/v2\/tags?post=7424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}