Forum Moderators: phranque
couldn't any malicious actor easily guess such a URL and brute force it?
Another suggestion: change the name of the server to something hard to guess
Oftentimes a control panel can also be accessed using the IP address, or any domain that resolves to it even
Does "access" mean access the cPanel log in page or access the cPanel home page?
I do not understand how that referrer could mean that my cPanel has been compromised
Additionally, the same IPs causing this referrer are blocked in an .htaccess file that otherwise works as it should. I.e. by using the referrer cpanel.example.com it appears to by possible to bypass the IP blocking. Any ideas?
A request will still appear in your access logs even when the IP address is blocked, because it still reaches the web server.