KB
cPanel & Hosting

cPanel Configuration Tweak

10 min read2096 words

At a glance#

  • Purpose: Recommended configuration changes for a production cPanel/WHM server covering security, mail and performance.
  • Applies to: cPanel & WHM on CloudLinux, AlmaLinux and CentOS.
  • Risk: Medium - several settings affect live hosting accounts.
  • Time: 2-3 hours to work through fully.
  1. csf+lfd checked and settings updated. Configuration can be done within WHM > ConfigServer Security & Firewall

Documentation: /etc/csf/readme.txt Website: https://www.configserver.com/cp/csf.html

  1. Running processes checked
  2. Checked system runlevel
  3. Stop unnecessary processes:

rpcbind

  1. Log Scanner has been enabled in /etc/csf/csf.conf and lfd will run hourly to email root log file summaries

Documentation: Look under LOGSCANNER in /etc/csf/csf.conf

  1. Logwatch installed

Documentation: /usr/share/doc/logwatch*/ Website: https://sourceforge.net/projects/logwatch/

  1. cPanel/WHM configuration check - the WHM options have been checked and where necessary modified for security and stability. The most important ones are as follows:

/Set "WHM > Tweak Settings > Max hourly emails" - this limits any damage caused by spammers should they get onto the server through an exploit Enabled "WHM > Tweak Settings > Always redirect to SSL" - enables secure access through SSL for logins Enabled "WHM > Tweak Settings > Require SSL" - enables secure access through SSL for logins Disabled "WHM > Tweak Settings > Email password reset" - this option has been an exploit vector in the past and should not be trusted Enabled "WHM > Apache mod_userdir Tweak" - this prevents users from stealing bandwidth or hackers hiding access to your servers through apache Disabled "WHM > Compiler Access" - this stops exploits from compiling code on you server "WHM > Change System Mail Preferences" - all these fields should be completed with an existing email address that is monitored Disabled "WHM > FTP Configuration > Anonymous FTP" - this is a typical vulnerable option used as an attack vector by hackers and should be disabled unless actively used Enable "WHM > Background Process Killer" - this kills off exploit processes such as IRC bots during the upcp nightly run Disabled "WHM > Tweak Settings > BoxTrapper spam trap" - it is trivial using this option to get your whole server listed on major RBL's. It also does nothing to combat spam overall and indeed adds to it Disabled "WHM > Tweak Settings > Proxy subdomains" - forces logins to be reported from remote host and not localhost due to proxy Disabled "WHM > Tweak Settings > Proxy subdomain creation" - forces logins to be reported from remote host and not localhost due to proxy Enabled "WHM > Tweak Settings > Hide login password from cgi scripts" - stops remote login password from being visible in environment variables Enabled "WHM > Shell Fork Bomb Protection" - this prevents poorly written scripts from consuming server resources and prevents local DOS attacks Disabled "WHM > Tweak Settings > Allow users to relay mail if they use an IP address" - POP before SMTP is considered a considerable security risk these days and should be disabled in favour os using SMTP AUTH by the end user email client

Disabled "WHM > Tweak Settings > Allow apps that have not registered with AppConfig to be run when logged in as a reseller to WHM." - If this breaks any plugins you need to contact the developer and have them fix it for cPanel AppConfig v2+ or re-enable this option Disabled "WHM > Tweak Settings > Allow apps that have not registered with AppConfig to be run when logged in as root or a reseller with the "all" ACL in WHM." - If this breaks any plugins you need to contact the developer and have them fix it for cPanel AppConfig v2+ or re-enable this option Disabled "WHM > Tweak Settings > This setting allows WHM applications and addons to execute even if an ACL list has not been defined." - If this breaks any plugins you need to contact the developer and have them fix it for cPanel AppConfig v2+ or re-enable this option Disabled "WHM > Tweak Settings > This setting allows cPanel and Webmail applications and addons to execute even if a feature list has not been defined." - If this breaks any plugins you need to contact the developer and have them fix it for cPanel AppConfig v2+ or re-enable this option

Enabled "WHM > Exim Configuration Manager > Require clients to connect with SSL or issue the STARTTLS command before they are allowed to authenticate with the server" - prevents password from being sent in plain text. If users have problems authenticating they need to use secure login, or disable this option Disabled "WHM > Exim Configuration Manager > Allow weak SSL/TLS ciphers" - prevent insecure SMTP connections

Other options are modified as per the csf Security Check Report in "WHM > ConfigServer Security & Firewall > Check Server Security > WHM Settings Check"

  1. The CloudLinux free symlink kernel patch has been applied, see:

https://www.cloudlinux.com/kernelcare-blog/entry/symlink-protection-patchset-centos-6-7-kernelcare

The patch is checked for updates every 4 hours using /etc/cron.d/kcare-cron

Note: You may see errors from the batch job when recently upgrading to the latest OS kernel until CloudLinux releases support for it

For servers running CloudLinux, the symlink patch has been enabled in /etc/sysctl.conf

  1. OpenSSH configured to only use SSHv2 and not perform DNS lookups
  2. Rootkit Hunter installed and configured and a twice daily cron job created to email a report to root. Can be run manually with:

/root/rkhunter.sh

rkhunter does throw some false-positives, e.g.:

Warning: The command '/sbin/ifdown' has been replaced by a script: /sbin/ifdown: Bourne-Again shell script text executable Warning: The command '/sbin/ifup' has been replaced by a script: /sbin/ifup: Bourne-Again shell script text executable Warning: The command '/usr/bin/GET' has been replaced by a script: /usr/bin/GET: a /usr/bin/perl -w script text executable Warning: The command '/usr/bin/ldd' has been replaced by a script: /usr/bin/ldd: Bourne-Again shell script text executable Warning: Checking for possible rootkit strings [ Warning ] Found string 'hdparm' in file '/etc/rc.d/rc.sysinit'. Possible rootkit: Xzibit Rootkit

Website: http://rkhunter.sf.net

  1. Chkrootkit installed and configured. This will also run twice daily from a cron job to email a report to root. Can be run manually with:

/root/chkrootkit.sh

The following errors are false-positives and can be ignored:

./chkrootkit: line 1480: [: : integer expression expected /proc/NNN/fd: No such file or directory /usr/lib/debug/usr/.dwz Possible Linux/Ebury - Operation Windigo installetd INFECTED (PORTS: 465)

For information on hidden processes/LKM detection, read here: https://support.configserver.com/knowledgebase/article/chkrootkit-outputs-hidden-processes-and-lkm-warnings

Website: http://www.chkrootkit.org

  1. ModSecurity OWASP rules added

These can be managed through the WHM ModSecurity Tools provided by cPanel.

We do not provide any support for the actual rules. For that, you would need to seek help from cPanel themselves.

ConfigServer ModSecurity Control (cmc) has also been installed to WHM to allow you to whitelist false-positive mod_security rule ID's on a global, per user or per domain level, or you can use the WHM ModSecurity Tools provided by cPanel.

Website: http://www.modsecurity.org Website: https://www.configserver.com/cp/cmc.html

  1. Tidy disk space: Done. The following applications will have been removed if installed to avoid conflicts with existing/new applications and/or are not required/desired on cPanel servers: apf, maldet, spri, bfd, prm, les, sim, lsm, nobody_check, pyxsoft, fail2ban, aast, , cpmalscan, ossec
  2. If necessary, switched to pure-ftpd
  3. Updates to /etc/sysctl.conf
  4. Added logrotation of cPanel and apache files to /etc/logrotate.d/
  5. Installed ConfigServer Outgoing Spam Monitor

Website: https://www.configserver.com/cp/osm.html

  1. Kernel: OK
  2. Check /tmp /dev/shm /var/tmp: OK
  3. Hard Disk check: OK
  4. Update Operating System check: OK
  5. Apache/PHP/MySQL check: OK
  6. MailScanner, MSFE (MailScanner Front-End), SpamAssassin, ClamAV, DCC, Vipuls Razor, ConfigServer Mail Queues have all been installed.

SpamAssassin has been configured to work from within MailScanner instead of directly in cPanel. The server-wide bayesian SpamAssassin filtering has also been enabled - this does take some time to train itself but within a few days this can help greatly in positively identifying spam.

Configuration for MailScanner is controlled from the files within the directory: /usr/mailscanner/etc/

The main configuration file in that directory is MailScanner.conf

MailScanner has been configured with sensible options and to use rulesets which are stored in the rules/ subdirectory. The usual way is to tag the spam and still deliver it so that you can filter it yourself. You can change that action to delete if you definitely don't want it.

Here is an online guide which we have written that you can duplicate for your users: https://www.configserver.com/mshelp/index.htm

There is a utility for restarting MailScanner which must be done if any files within /usr/mailscanner/etc/ are changed: service MailScanner reload

There is another utility that I've setup to run daily in the root crontab which checks /etc/localdomains and makes sure that there is an entry for any domain listed within the rules files: /usr/mscpanel/mscpanel.pl

MailScanner has also been configured to use the checksum services DCC and Vipuls Razor. It is also configured to use Clam Anti Virus clamd daemon.

MailScanner will scan on all the domains that you have on the server. SpamAssassin in cPanel has been disabled because it is not compatible when MailScanner is used to classify emails. MailScanner itself does run SpamAssassin and the MailScanner front-end accessible to users through cPanel provides their interface to configuration changes available for their domains . This does mean that the features within cPanel (e.g. the spambox and whitelist) no longer function, but are replaced by the front-end features that we have developed.

All occurences of :blackhole: and /dev/null in /etc/valiases/* have been replaced with :fail: as this is what's needed to block dictionary attacks.

The MailScanner front-end for cPanel has also been installed together with the latest version of MailControl: https://www.configserver.com/cp/msfe.html

You can upgrade MailScanner, MSFE (the front-end) and ClamAV in future through the WHM MailScanner interface.

If necessary I have opened egress ports in your firewall for the checksum services: DCC - out-bound UDP port 6277 DCC - out-bound TCP port 587 (for reporting spam) Razor - out-bound TCP port 2703

Documentation: /usr/mailscanner/docs/ Websites: http://www.mailscanner.infohttp://www.spamassassin.orghttp://www.clamav.nethttp://www.rulesemporium.comhttp://www.rhyolite.com/anti-spam/dcc/http://razor.sourceforge.net/https://www.configserver.com/free/fail.html

Additional Information: ConfigServer Knowledgebase: https://support.configserver.com/knowledgebase

If you wish to keep up to date with the work performed here and other cPanel related information, we would recommend that you view (and subscribe via RSS) to our blog: ConfigServer Blog: https://blog.configserver.com/

  1. Host spoof protection by modifying /etc/host.conf
  2. Exploit check: None found - The full report is available in /var/log/cxsreports/scan.log, please note that not all entries in this log file are necessarily exploits.
  3. Perl installation check: OK
  4. Installed ConfigServer Explorer if requested

Website: https://www.configserver.com/cp/cse.html

  1. Installed ConfigServer Mail Queues

Website: https://www.configserver.com/cp/cmq.html

  1. Installed ConfigServer Mail Manage

Website: https://www.configserver.com/cp/cmm.html

  1. Delete unnecessary OS users: Done
  2. Enhanced path protection: Done
  3. PHP Hardening: Done

The following functions have been disabled: disable_functions = show_source, system, shell_exec, passthru, exec, popen, proc_open

You may need to re-enable some of these if they break php applications by editing /usr/local/lib/php.ini and removing them from disable_functions and then restarting httpd

Note: If using EA4 php.ini files are stored in /opt/cpanel/ea-php*/root/etc/php.ini (and /opt/cpanel/ea-php*/root/etc/php.d/local.ini if present), only the currently installed versions of PHP will have been modified

  1. MySQL and Apache tuning: Done
  2. Remove SUID/GUID from binaries if not required: Done
  3. DNS open resolver: Checked and closed if necessary
  4. Installed ConfigServer eXploit Scanner:

Configured cxs to use the cxs Watch Daemon and email root on exception and has a log file in /var/log/cxswatch.log

Configured cxs to quarantine Viruses and Fingerprint matches to /home/quarantine

Configured cxs to email root on exception via mod_security (see /etc/cxs/cxscgi.sh)

Configured cron job to update cxs and clean the quarantine directory: /etc/cron.daily/cxsdaily.sh

Configured daily and weekly scans in /etc/cron.d/cxs-cron. The daily scan will scan files that have changed within the last 25 hours within users public_html/ directories. The weekly scan will scan all files within users public_html/ directories. Both scans will email their reports to the root forwarder on completion

We recommend that you read through the cxs documentation, in particular the RECOMMENDATIONS section of the documentation (from "cxs --help" or "WHM > ConfigServer eXploit Scanner > Documentation")

To run a comprehensive scan and quarantine known fingerprint matches and viruses, you may wish to use this cxs command:

/usr/sbin/cxs --report /var/log/cxsreports/scan.log --mail root --virusscan --quarantine /home/quarantine --qoptions Mv --ignore /etc/cxs/cxs.ignore --options OLfmMChexdDZRP --threads auto --all

(The above command should all be on one line.)

Please note we strongly recommend that you use quarantine ONLY for Fingerprint and Virus matches, as other types of matches will give false positives.

Documentation: /etc/cxs/install.txt /etc/cxs/reference.txt Documentation: "perldoc cxs" or "cxs --help" or "WHM > ConfigServer eXploit Scanner > Documentation" Documentation: https://support.configserver.com/knowledgebase/category/cxs Documentation: https://forum.configserver.com/viewforum.php?f=26 Website: https://www.configserver.com/cp/cxs.html

This package includes one week of informational support requests regarding any item of server management or cPanel configuration (any work that requires login usually attracts the hourly General Server Administration rate) directly related to the work that we have done. After this time, our General Server Administration rate for any issues may apply.