KVM *dump xml*

If you ever need to gain VNC access to a KVM virtual server and you are not sure what ip, port, or even password is needed to access VNC to a KVM VM, enter this from command line:

virsh dumpxml <kvm> –security-info

Replace <kvm> with the name of your virtual machine. You can get the names by running:

virsh list

Quickly (Un)Suspend Email in Cpanel

If you need to quickly suspend e-mail for an e-mail address in cPanel and do not want to do this via the GUI, issue the following from command line as root:

whmapi1 suspend_outgoing_email user=$cpuser

Of course you’ll want to replace $cpuser with the username of the cpanel account you’d like to suspend e-mail for. The same thing goes for un-suspending:

WHM (root) passwordless

If you ever need to login to WHM/cPanel and do not have the root password, there is a call to the API you can make from command line to temporarily give you access. Just issue the following from the command line as root:

whmapi1 create_user_session user=root service=whostmgrd locale=en

Clear systemd journal

Well I just had the liberty of clearing systemd journal in /var/log for the first time. I recommend using this command

 journalctl --vacuum-time=10d

The above command will clear the journal messages older than 10 days. I recommend setting this to 5 if you are needing space.

exim eXploit – cPanel

After some extensive reading and working through an older version of EXIM mail daemon which is commonly used in cPanel, it would appear there is a nasty bug in an older version of EXIM.


btmp and you

There is a file in /var/log called btmp. If you notice this file is abnormally large *say 2GB* while it should be in the less than 10MB zone, you are or had gone through an SSH Brute Force attempt.

This file logs all the attempts to log-in to your server via SSH. If you have thousands of failed logins this file grows fast. You can remedy the problem my changing the SSH port number or allowing SSH access to limited IP’s per /etc/hosts.allow .

If this is taking up space, delete it. You can issue a bunch of commands, I like to zero it out with echo.


