hack create account #133

Closed
opened 2026-04-05 20:25:32 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @ystartgo on 1/25/2025

CloudPanel version(s) affected

v2.4.2

Description

My cloudpanel was hacked and I registered two management accounts.
I don’t know how I got in.
The original administrative account password is not the password but two-step verification is not enabled.
I didn’t see the reason for the incident, so I had to reinstall the entire system using Ubuntu 22.04 64 Bit.

How to reproduce

Unable to reproduce and find the vulnerability

Possible Solution

Block the following IPs
218.92.0.136
92.255.85.253
185.147.124.54
85.31.47.195
92.255.85.107

Additional Context

No response

*Originally created by @ystartgo on 1/25/2025* ### CloudPanel version(s) affected v2.4.2 ### Description My cloudpanel was hacked and I registered two management accounts. I don’t know how I got in. The original administrative account password is not the password but two-step verification is not enabled. I didn’t see the reason for the incident, so I had to reinstall the entire system using Ubuntu 22.04 64 Bit. ### How to reproduce Unable to reproduce and find the vulnerability ### Possible Solution Block the following IPs 218.92.0.136 92.255.85.253 185.147.124.54 85.31.47.195 92.255.85.107 ### Additional Context _No response_
Sign in to join this conversation.