Emergency server help: get in touch

Security

Security guides and tools: hardening cPanel, DirectAdmin and Linux servers, firewalls, malware scanning, CVE fixes and incident response.

Harden Shared cPanel Server: Secure CageFS and ModSecurity Setup

A layered hardening plan for multi-tenant cPanel hosts on CloudLinux or AlmaLinux, covering CageFS isolation, ModSecurity with the OWASP Core Rule Set, and malware scanning with Imunify360, ImunifyAV or ClamAV.

September 29, 2026

Hardening CSF safely: disabling Messenger, remote lists and other risky options

A settings-level review of csf.conf for hosting servers after the 2026 CSF vulnerabilities, covering which options widen the attack surface, what to turn off, what to tighten, and how to confirm the running firewall matches the file.

September 29, 2026

DirectAdmin External Account Binding: Paid CA Setup in 1.711+

How to connect DirectAdmin's built-in ACME client to a commercial certificate authority using External Account Binding credentials, which providers to expect, how to hide the ones you do not sell, and how to confirm certificates are coming from the paid account.

September 29, 2026

DirectAdmin ModSecurity: Secure OWASP CRS Setup

How to turn on ModSecurity 3 through CustomBuild with the OWASP Core Rule Set or the Comodo ruleset, where the rules and audit log live, and how to write per-domain exclusions so one false positive does not mean disabling the firewall for everyone.

September 29, 2026

DirectAdmin ACME TLS Migration (1.706+): Safe Step-by-Step Plan

What DirectAdmin's ACME-driven TLS system introduced in 1.706 changes compared with the old letsencrypt.sh flow, how the migration task added in 1.708 moves existing domains across, and the settings and failure modes to check afterwards.

September 29, 2026

Mitigating Copy Fail, Dirty Frag and the DirectAdmin 1.711 TLS privilege escalation

Applying the kernel-side mitigations for the 2026 Copy Fail, Dirty Frag and Fragnesia local privilege escalations on DirectAdmin servers, updating to 1.711 for the TLS system fix, and verifying that each mitigation is actually in force.

September 29, 2026

DirectAdmin Certificate Not Renewing: Fix Failed Renewals

A diagnostic path for DirectAdmin domains whose certificates stop renewing under the ACME TLS system, from the Provisioning history page added in 1.710 through lego's error messages to the failure counter that silently disables a domain.

September 29, 2026

CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting

A practical comparison of the three products hosting providers most often evaluate after leaving CSF, covering what each one protects, how it integrates with cPanel and plain Linux, cost structure, operational load and which fleet each one suits.

September 29, 2026

CSF Fork 2026: Which Reliable Replacement After ConfigServer?

A comparison of the maintained CSF forks a year after ConfigServer closed, covering who maintains each one, which panels and operating systems they target, how they update, and which one fits a given fleet.

September 29, 2026

CSF AlmaLinux 10: nftables and ipset Problems Fixed

Why CSF behaves differently on AlmaLinux 10 and other EL10 systems, how the iptables-nft compatibility layer changes rule handling, why ipset-backed blocklists fail, and the settings that keep LFD useful while you choose a longer-term fix.

September 29, 2026

CSF CVE-2026-65638, 65639, 67402: Critical Patch Guide

What the three CSF vulnerabilities disclosed in August and September 2026 allow, which versions are affected, how to confirm a server is exposed, and the exact settings and versions that close each one on cPanel and standalone Linux servers.

September 29, 2026

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.