[
MAINHACK
]
Mail Test
BC
Config Scan
HOME
Create...
New File
New Folder
Viewing / Editing File: control_panel_protector.py
File is not writable. Editing disabled.
import time from logging import getLogger from defence360agent.contracts.messages import MessageType from defence360agent.contracts.plugins import ( MessageSink, MessageSource, expect, ) from im360.contracts.config import ControlPanel from im360.contracts.config import ( ControlPanelProtector as ControlPanelProtectorConfig, ) from im360.subsys.panels.cpanel import cPanel from im360.subsys.panels.hosting_panel import HostingPanel logger = getLogger(__name__) class ControlPanelProtector(MessageSink, MessageSource): PLUGIN_ID = ControlPanelProtectorConfig.PLUGIN_ID def __init__(self): self.loop, self.sink = None, None self.panel = HostingPanel() async def create_sink(self, loop): self.loop = loop async def create_source(self, loop, sink): self.loop = loop self.sink = sink @expect(MessageType.EnduserPasswordReset) async def process_password_reset_request(self, message): if not ControlPanel.COMPROMISED_USER_PASSWORD_RESET: return usernames = message.get("usernames", []) if not isinstance(self.panel, cPanel): logger.info( "Ignoring password reset for users %s: cPanel only", usernames ) return for username in usernames: try: self.panel.force_reset_user_password(username=username) except Exception: logger.exception( "Failed to change password for user %s", username ) else: await self.sink.process_message( MessageType.SensorIncident( name=( "cPanel account password reset for user" f" {username}" ), plugin_id=self.PLUGIN_ID, rule="1", severity=15, timestamp=time.time(), message=( f"cPanel account {username} is compromised." " Password is reset to prevent further" " malicious access. The owner can restore" " access to the account via email." ), ) )
Save Changes
Cancel / Back
Close ×
Server Info
Hostname: server05.hostinghome.co.in
Server IP: 192.168.74.40
PHP Version: 7.4.33
Server Software: Apache
System: Linux server05.hostinghome.co.in 3.10.0-962.3.2.lve1.5.81.el7.x86_64 #1 SMP Wed May 31 10:36:47 UTC 2023 x86_64
HDD Total: 1.95 TB
HDD Free: 691.35 GB
Domains on IP: N/A (Requires external lookup)
System Features
Safe Mode:
Off
disable_functions:
None
allow_url_fopen:
On
allow_url_include:
Off
magic_quotes_gpc:
Off
register_globals:
Off
open_basedir:
None
cURL:
Enabled
ZipArchive:
Disabled
MySQLi:
Enabled
PDO:
Enabled
wget:
Yes
curl (cmd):
Yes
perl:
Yes
python:
Yes
gcc:
Yes
pkexec:
No
git:
Yes
User Info
Username: itsweb
User ID (UID): 1619
Group ID (GID): 1621
Script Owner UID: 1619
Current Dir Owner: N/A