Emergency server help: get in touch

Security

Security guides and tools: hardening cPanel, DirectAdmin and Linux servers, firewalls, malware scanning, CVE fixes and incident response.

Force HTTPS for a Domain in DirectAdmin (Tested on 1.712)

Redirect every http:// address of a DirectAdmin domain to https:// with Force SSL, from the panel or the API, and check it with a redirect test. Tested on DirectAdmin 1.712.

October 6, 2026

Install FreePBX 17 on Debian 12 (Open-Source Only, Tested)

Install FreePBX 17 with Asterisk 22 on Debian 12 using the official script, get past the oracle_connector failure with --opensourceonly, secure the admin login and fix fail2ban. Tested 6 Oct 2026.

October 6, 2026

Find cPanel, DirectAdmin and MySQL Passwords from the CLI (and One-Time Login Links)

Short answer: cPanel and DirectAdmin do not keep the root, WHM or admin password anywhere you can read it back. They are normal Linux user passwords, stored only as hashes in /etc/shadow. You either reset them or, better, log in with a one-time login link created from the command line. What you can read as

October 6, 2026

fail2ban for Asterisk and FreePBX: Block SIP Password Guessing

Set up fail2ban for Asterisk PJSIP: turn on the security log, confirm the stock filter matches with fail2ban-regex, create a jail that reads the right files, test a ban, and keep your SIP provider and office off the ban list.

October 3, 2026

SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense

Generate firewall rules for Asterisk, FreePBX and other SIP servers: SIP limited to your provider and phones, the RTP range open, scanner protection, and the matching rtp.conf and PJSIP NAT settings.

October 3, 2026

Server hacked: incident response runbook for Linux and cPanel Pro

An incident response runbook for a hacked Linux or cPanel server: contain it, preserve evidence, find the entry point, decide clean or rebuild, rotate credentials in the right order and tell customers.

September 30, 2026

Access Log Top IPs and Bots Report

An access log top IPs report for Apache, LiteSpeed and Nginx: top IPs, agents, URLs, fake Googlebots, 404/5xx and wp-login or xmlrpc floods for the last minutes or hours, across all vhosts.

September 30, 2026

cPanel PHP Version Audit

A cPanel PHP version audit for EasyApache 4 MultiPHP: every domain's PHP version, a count per version, and a list of sites still running end-of-life PHP. Optional CSV export.

September 30, 2026

AutoSSL DCV Failures Report

Lists AutoSSL DCV failures on a cPanel server grouped by cause (DNS elsewhere, CAA, rate limit, blocked /.well-known/) and every installed certificate that expires within 14 days.

September 30, 2026

WP Toolkit CVE-2026-87900: what is affected and how to patch to 6.11.3

WP Toolkit CVE-2026-87900 is a critical argument-injection flaw in WP Toolkit for cPanel 6.11.2-10794 and earlier. Which versions are affected, how to confirm the fix, and what to check afterwards.

September 30, 2026

Server Security Audit Script

A read-only server security audit script for Linux: SSH, firewall, brute-force protection, updates, ports, sudo and filesystem checks as PASS/WARN lines. Checks it cannot run are SKIP, never PASS.

September 30, 2026

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.