cPanel Server Services

This comprehensive server service is offered for servers running cPanel. We will perform the installation, configuration and testing of each component of the service. We do not use scripts to perform this work (as some providers do) but perform each task by hand to ensure it is correctly installed and configured to your server’s requirements.

The aim of this work is to:

  • Help secure your server from attack
  • Perform server tuning to better cope under load
  • Provide relevant regular information from your server to identify any security breaches or anomalous behaviour
  • Check for existing exploits installed or running on the server

We aim to begin the work on your server within 24 to 72 hours from the opening of a ticket on our helpdesk with the answers to our installation questions (and correct access details) which we will send to you once your order has been processed.

cPanel Service Package Only

$130/server

cPanel Service Package plus MailScanner

$160/server

Included in the cPanel Server Service:

lfd is integrated with csf to block hacking attempts from your internet facing services and detects system intrusions/rootkits.

Log Scanner is part of lfd and is configured to send you email summaries once per hour using regular expression matches on the major server log files.

Mod_security apache module is a security layer in apache that helps prevent exploitation of vulnerable web scripts. We will install and configure the optional cPanel ModSecurity Apache module and include a set of effective rules. See note 4 below.

Check that the correct kernel is installed and upgrade to the OS vendor's latest version if necessary and implement tweaks to help protect against current threats (e.g. disabling core file creation). See note 5 below.

Check to ensure that the server’s OS is updated and, if not, an update is run.

If cPanel has just been installed but not configured we can do this for you.

Check that apache is correctly configured and tuned for your server's requirements and that it is the latest version, and upgrade if necessary. See note 3 below.

Check that mysql is correctly configured and tuned for your server’s requirements. See note 3 below.

Check temporary file permissions, ownership and contents. Remount noexec and nosuid where possible.

Pure-ftpd is considered more secure and lighter on server resources compared to proftpd on cPanel servers.

On a standard OS installation many user accounts are created that are not necessary and can therefore pose a security risk.

Default OS configurations often run services that are not used by a cPanel web server and can be a security risk if left running.

On a standard OS installation many application binaries have SUID and GUID bits set that are not necessary and can therefore pose a security risk.

Ensure disks are correctly mounted and clean up any old files to free space where possible.

If applicable, the free CloudLinux Symlink Kernel Patch will be applied.

The MailScanner Front-End plugin is included with the cPanel Service Package + MailScanner package

The cxs plugin is included free with our cPanel Service Package. Please read through the notes and limitations here and on the cxs page and the cxs FAQ

We will run a manual cxs scan of user data to help identify any exploits within accounts and provide a summary report of the results. Also checks in commonly abused disk directories such as /tmp and /dev/shm for any active exploits as well as a scan of all running processes. If exploits are found on the server, the compromised account can be suspended and we will notify you of the location of the exploits. This scan does not include identifying specific exploits, restoring/cleaning any compromised scripts, or quarantining exploits for you.

The osm cPanel plugin is included free with our cPanel Service Package. Please read through the requirements and limitations on the osm page and the osm FAQ.

cmm is a WHM plugin that allows you to edit, view and manage client email accounts and quotas from within WHM without having to log into their cPanel account.

The cmq plugin allows you to check within WHM and clear the servers exim queue(s) and deal with individual emails awaiting delivery.

The cmc WHM plugin allows you to control the disabling of mod_security rules by their ID on a global, per user and per domain level.

cse is a WHM plugin that allows you to browse your disk structure and directories and perform shell tasks from within WHM which can be very helpful if SSH fails for any reason.

Logwatch is a daily report that summarises the information contains in the major server log files.

Dynamic Library loading is disabled, commonly abused php functions disabled, user defined php.ini files disabled if suPHP is already enabled - to help prevent hackers exploiting vulnerable PHP web scripts.

Rootkit Hunter is an essential tool in detecting possible root compromise and rootkit installation.

Chkrootkit is another essential tool in detecting possible root compromise and rootkit installation. It complements rkhunter with a different detection approach.

OpenSSH is checked to ensure only SSHv2 protocol is enabled.

Help protect against clients and hackers browsing and accessing files outside of their account directories.

Check whether the server is running the latest supported version of cPanel and if not, upgrade it.

WHM configuration options are checked for security and performance configuration and changed where deemed appropriate.

Having boxtrapper enabled can very easily lead to your server being listed in common RBLs and usually has the effect of increasing the overall spam load, not reducing it.

You can raise technical queries on our helpdesk for one week after the service package is performed. Any additional work requiring us to login to your server may attract our hourly general server support fee.

Notes

  1. We no longer provide support for Virtuozzo or OpenVZ servers for csf or cxs. While the products may work on these types of containers, there may be issues that we cannot support.
  2. Some servers with monolithic kernels (i.e. does not use Loadable Kernel Modules – LKMs) need to have specific iptables modules loaded and it may not be possible to configure an iptables firewall. This usually only applies to those with custom kernels or VPS hosts that have not compiled their Virtuozzo kernels with iptables support.
  3. We will upgrade Apache, PHP or MySQL to the latest minor version of the major version you have chosen (e.g. Apache v2.2 to v2.4). If you want us to upgrade to a the latest major version of an application, you must expressly say so. Tuning is a basic configuration appropriate for the server configuration.
  4. While we will try and help with issues arising from the use of ModSecurity, we cannot provide direct support for the rules which should be sought from the provider’s support site.
  5. We do not offer a service to investigate or fix issues with OS vendor kernel upgrades, so you must ensure that you have suitable backups.

Requirements and Limitations

  • The cPanel Service packages can be performed on dedicated servers and VPS’s running cPanel supported releases on Redhat/CentOS/AlmaLinux/CloudLinux and Ubuntu (i.e. not EOL)
  • We cannot perform this work on servers running the applications from 1h.com, BetterLinux, Bitninja or ASL.
  • cPanel must be installed before we can perform this service package (its is a prerequisite)
  • We cannot provide any guarantees that the work that we do won’t affect third-party applications (including web scripts). We can advise after the work is done if you see any problems where to start looking, but we don’t provide any support for third party applications (including web scripts). Any advice that we give is dependent on you performing normal server administration investigative work into any problems and implementing any suggestions that we may provide.
  • This is a service that we perform for you, not a package of applications that you can download and install yourself.