{"id":67337,"date":"2024-10-29T14:17:06","date_gmt":"2024-10-29T14:17:06","guid":{"rendered":"https:\/\/devel.www.cpanel.net\/?p=67337"},"modified":"2024-10-29T14:18:51","modified_gmt":"2024-10-29T14:18:51","slug":"from-detection-to-action-handling-fraudulent-cpanel-whm-licenses","status":"publish","type":"post","link":"https:\/\/devel.www.cpanel.net\/blog\/security\/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses\/","title":{"rendered":"From Detection to Action: Handling Fraudulent cPanel & WHM Licenses"},"content":{"rendered":"\n
Don’t let fake cPanel licenses ruin your business. Fraudsters are on the rise, targeting both Partners and end-users. In this blog, we’ll expose their tactics, provide tools to protect yourself, and guide you toward legitimate licensing solutions. It’s time to take a stand against fraud and ensure the security and integrity of your cPanel environment.\u00a0<\/p>\n\n\n\n
Do you ever encounter pricing for a high cPanel license tier that seems almost too good to be true? Do you attempt to contact your license provider for cPanel troubleshooting only to get the run-around? Does your license provider or host need to frequently \u201creplace\u201d the installed cPanel license on your server? These are some indicators of red flags with fraudulent retailers. <\/p>\n\n\n\n
Fraudsters will also claim that they are using a \u201cGPL\u201d version of a cPanel license to back up their false claim of legitimacy. GPL stands for General Public License, a license type that allows users to copy, modify, and otherwise share applicable software for distribution as they see fit. To be clear, there are no GPL versions of cPanel & WHM. <\/p>\n\n\n\n
Due to how cPanel\u2019s licensing system functions, fraudsters need to go to great lengths to \u201ccrack\u201d the mechanisms we have in place by configuring license circumvention scripts and software. This software is installed at the root level and almost always contains additional backdoors. Independent security investigations have found known compromises related to these licenses. <\/p>\n\n\n\n
Because these licenses also try to evade our licensing servers, they often will not receive important updates containing vital security patches. This can leave your server and website vulnerable to third-party exploits. <\/p>\n\n\n\n
In the event a user of a circumvented license reaches out to cPanel support for assistance, unfortunately, we must consider the associated server as root compromised, and we will not be able to provide support. The only actions that can be considered to address a root compromised server reasonably are to perform a fresh Operating System and WHM\/cPanel installation and restore account backups, or to migrate the accounts to a known clean server that has not been previously root compromised. <\/p>\n\n\n\n
You want to believe you can trust a vendor, but if some of the red flags we outlined above sound all too familiar then you need to verify claims that the license you purchased from them is legitimate. Fortunately, verify.cpanel.net<\/a> is free and easy to use at any time.<\/p>\n\n\n\n Or, sometimes using an inappropriate license type such as:<\/p>\n\n\n\n The cPanel DNSOnly license<\/a> type is for the creation of dedicated nameservers and can replicate DNS zones to create a DNS cluster with other servers. This license type is not intended to serve actual website data<\/strong> and therefore, cannot be used to create cPanel accounts. Fraudulent license providers often circumvent our licensing system with the use of cPanel DNSOnly license types. <\/p>\n\n\n\n As previously mentioned, we consider any servers the fraudulent licenses are associated with as root compromised. Firstly, you must procure a new server to prepare for a migration of your cPanel\/WHM server data. If you also purchased hosting services from the same vendor of the fraudulent license, cPanel has a directory of verified Partners<\/a> with a variety of hosting options to choose from. <\/p>\n\n\n\n These verified Partners will also bundle cPanel & WHM licenses with their hosting services. Alternatively, purchase a license directly from store.cpanel.net<\/a> if you are self-hosting. <\/p>\n\n\n\n With a new server and valid license in hand, it is time to migrate your website data to your new server. If you still have access to the old server with the license intact, you can utilize Transfer Tool to automate the migration.<\/a><\/p>\n\n\n\n If you find that the circumvented license is non-functional, sites and configuration files will need to be migrated manually. We have guides available to help you in the manual transfer process, using either cpconftool script <\/a>or using pkgacct and restorepkg<\/a>.<\/p>\n\n\n\n If you have any questions about cPanel licensing, feel free to reach out to one of our verified Partners through our PartnerNoc directory, partnernoc.cpanel.net<\/a>. Alternatively, contact cPanel Customer Service directly.<\/a><\/p>\n\n\n\n By staying informed, using the tools provided, and working together, we can protect our businesses and ensure a secure cPanel ecosystem for all. <\/p>\n","protected":false},"excerpt":{"rendered":" Don’t let fake cPanel licenses ruin your business. Fraudsters are on the rise, targeting both Partners and end-users. In this blog, we’ll expose their tactics, provide tools to protect yourself, and guide you toward legitimate licensing solutions. It’s time to take a stand against fraud and ensure the security and integrity of your cPanel environment.\u00a0 […]<\/p>\n","protected":false},"author":109,"featured_media":67341,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[2281],"tags":[89,2333],"class_list":["post-67337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cpanel","tag-fraud-prevention"],"acf":[],"yoast_head":"\nHow to verify a license<\/h3>\n\n\n\n
\n
\n
<\/figure>\n\n\n\n
\n
<\/figure>\n\n\n\n
\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
A note on DNSOnly licenses<\/h3>\n\n\n\n
What Do I Do Now?<\/h2>\n\n\n\n
A Helping Hand<\/strong> <\/h2>\n\n\n\n