frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

CPanel and WHM Authentication Bypass – CVE-2026-41940

https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
47•zikani_03•3h ago

Comments

0xbadcafebee•1h ago
Y'know what would help protect those internet buildings from falling on people? A software building code
debo_•1h ago
I wonder how much of the web still runs on perl. I miss it sometimes.
mushufasa•1h ago
I used to help nonprofits and small businesses build websites. Process always went like 1. buy domain, 2. buy a shared hosting provider that one-click-installs Wordpress, 3. use a theme to begin editing the website. Often, I would also use the email included with that hosting provider for the firm.

ALL of that goes through cpanel, for every shared hosting provider I can ever remember using. Even if the stuff happening on those servers didn't use perl, cpanel itself -- the admin of everything provided for that domain by the hosting provider -- it's a huge surface area.

mushufasa•1h ago
Oh dear.
superasn•1h ago
Everytime I read one of these it always boils down to the same thing..Don't solve solved problems. And the best code in this case is code you didn't write as PHP's session handler is battle-tested but every line you write to roll your own is a line you have to secure, maintain, and eventually patch at 2am when someone finds the bug.

Session handling, auth, crypto, password hashing etc - all these are the exact areas where you should be the most allergic to rolling your own. Not because you're not smart enough, but because a simple bug like sanitizing in the wrong place and the failure is catastrophic like in this instance.

Use boring, proven, widely-audited solutions. Save your creativity for the actual problem you're solving.

ryandrake•1h ago
I don't even know why you'd want to re-implement this stuff, too. It's not exciting or sexy work. It's like time parsing, time zone handling, leap years... Why would you want to inflict that on yourself? You will 100% not handle every edge case, and you will 100% get time and time zone handling bugs.
bananamogul•1h ago
“And the best code in this case is code you didn't write as PHP's session handler is battle-tested”

cPanel is written in perl.

superasn•31m ago
Oh you're right to push back. I just love saying this nowadays :P Anyway, I haven't used these languages in a long time but the code looked like php to me, though I did notice the .pm file extension and wondered where I've seen it before.
shawnz•47m ago
cPanel is 30 years old, are you saying it's not battle tested, boring, proven, and widely audited?

In fact PHP is only a few months older than it.

yabones•1h ago
Oooooh that's really bad. Wordpress on Cpanel sites is like the Dark Matter of the internet, it's everywhere and you don't see it until something bad happens. Libations for the sysadmins patching & cleaning up this mess.
xtracto•6m ago
At the rate we are going, we will all go back to publish HTML website like in Geocities times.
Loudergood•1h ago
That's gonna pair really well with this.

https://copy.fail

yunnpp•1h ago
Why? This one gives you a root shell directly, no need for an LPE.
ChrisArchitect•1h ago
Earlier: https://news.ycombinator.com/item?id=47967974
ls612•57m ago
Something that is starting to concern me with the flood of cyber chaos in the past couple of months is my homelab. Currently I do not have it set up to be accessible outside the local network and then add it and all my other devices to my tailnet to facilitate remote access (via an exit node on my local network). On top of that TrueNAS doesn't seem to have the best update cadence so I'm worried about having a system with known vulnerabilities only protected by not being accessible remotely in theory.
whalesalad•13m ago
> this vulnerability affects - and we cannot stress this enough - all currently supported versions of cPanel & WHM

yikes. https://www.shodan.io/search?query=basic+realm%3D%22cPanel%2...

OpenWarp

https://openwarp.zerx.dev
16•zero-lab•34m ago•10 comments

How Mark Klein told the EFF about Room 641A [book excerpt]

https://thereader.mitpress.mit.edu/the-whistleblower-who-uncovered-the-nsas-big-brother-machine/
445•the-mitr•10h ago•141 comments

Opus 4.7 knows the real Kelsey

https://www.theargumentmag.com/p/i-can-never-talk-to-an-ai-anonymously
183•ilamont•1d ago•108 comments

For Linux kernel vulnerabilities, there is no heads-up to distributions

https://www.openwall.com/lists/oss-security/2026/04/30/10
388•ori_b•10h ago•311 comments

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/
332•j12y•10h ago•112 comments

Can I disable all data collection from my vehicle?

https://rivian.com/support/article/can-i-disable-all-data-collection-from-my-vehicle
523•Cider9986•6h ago•199 comments

CPanel and WHM Authentication Bypass – CVE-2026-41940

https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-auth...
47•zikani_03•3h ago•16 comments

I built a Game Boy emulator in F#

https://nickkossolapov.github.io/fame-boy/building-a-game-boy-emulator-in-fsharp/
224•elvis70•9h ago•48 comments

Claude Code refuses requests or charges extra if your commits mention "OpenClaw"

https://twitter.com/theo/status/2049645973350363168
982•elmean•12h ago•552 comments

Maladaptive Frugality

https://herbertlui.net/maladaptive-frugality/
22•herbertl•2d ago•5 comments

Vercel’s pricing page

https://theupsellgame.com/
112•bartoindahouse•6h ago•21 comments

How an oil refinery works

https://www.construction-physics.com/p/how-an-oil-refinery-works
341•chmaynard•12h ago•102 comments

New mechanical panoramic film camera from Jeff Bridges

https://wideluxx.com
86•armadsen•2d ago•37 comments

Reverse Engineering SimTower

https://phulin.me/blog/simtower
129•patrickhulin•2d ago•20 comments

You can beat the binary search

https://lemire.me/blog/2026/04/27/you-can-beat-the-binary-search/
267•vok•3d ago•124 comments

Belgium stops decommissioning nuclear power plants

https://dpa-international.com/general-news/urn:newsml:dpa.com:20090101:260430-930-14717/
760•mpweiher•14h ago•718 comments

Snowball Earth may hide a far stranger climate cycle than anyone expected

https://sciencex.com/news/2026-04-snowball-earth-stranger-climate.html
42•wglb•4h ago•5 comments

Durable queues, streams, pub/sub, and a cron scheduler – inside your SQLite file

https://honker.dev/
180•ferriswil•12h ago•51 comments

Full-Text Search with DuckDB

https://peterdohertys.website/blog-posts/full-text-search-w-duckdb.html
98•ethagnawl•8h ago•23 comments

10Gb/s Ethernet: what I did to get it working in my home

https://www.gilesthomas.com/2026/04/10g-ethernet-what-i-did
152•gpjt•1d ago•108 comments

Show HN: What happens when you load a webpage (Interactive)

https://toolkit.whysonil.dev/how-it-works/internet-timeline/
7•otterwilde2•3d ago•1 comments

I aggregated 28 US Government auction sites into one search

https://bidprowl.com
249•scarsam•14h ago•73 comments

Does Postgres Scale?

https://www.dbos.dev/blog/benchmarking-workflow-execution-scalability-on-postgres
88•KraftyOne•7h ago•43 comments

The Church Rock Uranium Mill Spill

https://en.wikipedia.org/wiki/Church_Rock_uranium_mill_spill
64•Sir_Twist•2d ago•4 comments

A Milestone in Formalization: The Sphere Packing Problem in Dimension 8

https://www.alphaxiv.org/abs/2604.23468
16•measurablefunc•2d ago•0 comments

SimpleX Channels, SimpleX Network Consortium and Community Crowdfunding

https://simplex.chat/blog/20260430-simplex-channels-v6-5-consortium-crowdfunding-freedom-of-speec...
21•pmw•5h ago•2 comments

Compositing and Blending – Exploring the math and intuition behind blend modes

https://nik.digital/posts/compositing-blending
18•OuterVale•1d ago•2 comments

Spain's parliament will act against massive IP blockages by LaLiga

https://www.democrata.es/en/politics/congress-and-senate/congress-will-act-against-massive-ip-blo...
420•akyuu•11h ago•175 comments

Follow-up to Carrot disclosure: Forgejo

https://dustri.org/b/follow-up-to-carrot-disclosure-forgejo.html
46•homebrewer•7h ago•7 comments

The Accidental Ancestor – How Verifying Numbers Shaped Modern Hashing

https://0xkrt26.github.io/math_behind_security/2026/04/28/the-accidental-ancestor-Luhn-algorithm....
12•denismenace•2d ago•0 comments