PDA

View Full Version : Bypassing Vportal to install Lxadmin


himagain
12-11-2009, 04:16
I can't get any response out of vportal console.
I don't want to install the only two options of CPanel and DA. I want to install LXAdmin(Kloxo-horrible name!) which I've been very happy with until my VPS Hosts have gone west....

Don't even know what Putty is outside of a sealant. :-)
But anything directly entered in theConsole doesn't appear to do anything. vis:
wget http://download.lxlabs.com/download/kloxo/production/kloxo-install-master.sh

I was supplied with lxadmin all setup previously and it had very easy additional program instals and auto upgrade and best of all - free... :-)
I want to be able to instal softaculous (http://softaculous.com) or installapp.

How would I install even a good forum like SMF on my VPS?

Cheers, in non-geekness,
Himagain

RobM
12-11-2009, 12:43
I don't think your going to get a reply in here about LXAdmin as there are Major security holes in there software. Just search google and you will see and your just asking to be rooted.

Also burst/nocster will not / don't support that product.

You best bet is to install cPanel or Directadmin.

himagain
12-11-2009, 14:20
Hi Rob and anyone who happens by (quiet as a tomb in here...),

I simply don't believe the negatives out there about Lxadmin - VERY expensive real professionals warned me after I was totalled twice a couple of years ago, NEVER use CPanel - and they showed me what happened to my Server.
I'm no geek - but I've been around a loooong time. I also know that if someone targets you and you are running an "open" box like CPanel or any other, you are gone. It's just a lottery.

I won't be running an open system ever again.
FYI:
The whole negativity schema about Hypermin and Lxadmin was based around ONE assault (no proof - just assumptions) and the particular bug that was isolated was fixed at once.
The particular hosting company involved was not run by first class professionals (like 99.9999% of the industry) either.

IF it was so faulty - the untold numbers of systems running the packages would have *ALL* been trashed long ago by the scriptkiddies.
A good lesson for all would be to follow that story and take note of WHO does the trashing of hypervm/lxadmin/kloxo. It's as fascinating as the Xangelz saga.

My own early operations were regularly targeted on two grounds - contentious material and a wilful person circulating my details to the scriptkiddies forums.
Finally, a VERY expensive *real* pro told me that running any sort of CPanel/DirectAdmin/ETC and letting the public in is automatically an open door - or should we say "Windows" .
He *demonstrated* how simple it was to go virtually anywhere he wanted.
(He walked us in to a couple of VERY "secure" Sites, admittedly running Microsoft Servers)

So, I retired from that end. I now fully understand that Burst could be hit any time, too. The nice people here are welcome to it. :-)
It's all just a hobby for me now.
I understand much more these days and like a smart person (vis: one who realises that due diligence is everything PLUS luck) won't go where the sharks gather.
So, with no open doors, or Windows, *NO* public access to the System and these days just a quiet little hobby operation, a good little package like Lxadmin is all I want.
AND it doesn't attract the scriptkiddies like the others.
It has the reputation of being too easy - no kudos!! Ha!

Cheers,

RobM
12-11-2009, 20:57
Finally, a VERY expensive *real* pro told me that running any sort of CPanel/DirectAdmin/ETC and letting the public in is automatically an open door - or should we say "Windows" .
He *demonstrated* how simple it was to go virtually anywhere he wanted.
(He walked us in to a couple of VERY "secure" Sites, admittedly running Microsoft Servers)

I would agree that anybody can get into an unsecured server... but if you secure and keep the security update to date your 99.9% not getting in.

Now the person who said cPanel/DirectAdmin are unsecure does not know either products. Both are VERY secure when setup correctly.

Please remember cPanel was born right here at Burstnet way back in the day when Nick work for burstnet. Back then burstnet was the only place you could get it...

If you google and you can find alot of the holes in Kloxo.

Also If I find the post again, even there (Kloxo) coder admitted holes in his coding...

himagain
12-11-2009, 21:32
Hi Rob,
That's fascinating info! I remember the early days of CPanel. I was here before the Net was even a gleam in Marc Andreessen's eye, in fact before he was a gleam in Mrs Andreessen's eye.

I was also a super-early adopter of WHM/CPanel.

You misunderstood my post:
The girl in question is one of the world's best hackers. She simply showed me how easy it is to get into almost anything - CPanel was obvious because it is 90% of the market - like Microsoft. Even I was taught how easy it was to get into anything MS. ANYTHING can be cracked.
It is simply a question of being targeted.

THEN how good the hacker is, compared to the defence - and if you have openings - because you have to - you are behind the 8-ball ipso facto.

It would be a brave ***** to publicly go out today and say "I'll pay $100,000 to anyone who gets in here", when even scriptkiddies have 6-8000 Microsoft P.C. zombies.

The simple fact is though, that virtually all compromised systems are inside jobs, deliberate or dumb.

So, at the end of the day, I'm not just knocking CPanel it's the system. But the exploit that I was shown for CPanel was no dofferent to Plex and there were 3 then........
My first big loss was due to CPanel intrusion - and no real security from my "managed" Server.

If I could only afford her time.................

Anyway, back to work. But I do like to see things straight and fair in this unfair world. :-{

I still need to get into my little VPS.

Cheers!