


Major security breach of pagoda panel! Webmaster needs urgent security updates (with plan)
Yesterday (August 23, 2020), a major security vulnerability occurred in Pagoda Panel, one of the two well-known server environment tools in China!
Footnote: The two well-known server environment tools are 小piPanel (phpstudy) and Pagoda Panel (a rising star)
This update is an emergency security update. Users of Liunx version 7.4.2 and Windows version 6.8 must update to the latest version (other versions are not affected). To update, log in to the panel and click Update in the upper right corner of the homepage. Can.
Note: If the database is maliciously deleted, after upgrading the panel, if you do not understand the database recovery mechanism, please do not do other operations. It is recommended to shut down directly and then find a professional. Operation methods to assist in recovering data errors may reduce the probability of later data recovery. If you need assistance with data recovery, please contact official customer service.
Users of Linux version 7.4.2 and test version 7.5.14 are updated to the following versions
Pagoda linux test version 7.5.15 (security version)
Pagoda linux official version 7.4.3 (security version)
This update is an emergency security update. Users of 7.4.2 must update to the latest version
Update method :
Log in to the panel backend, click Update in the upper right corner, after the pop-up window, click Update Now
or use the upgrade script (Note: Prioritize Click Update directly on the home page of the panel. Only use this command if it fails, and it cannot be executed in the SSH terminal that comes with the panel):
curl https://download.bt.cn/install/update_panel.sh|bash
Offline upgrade steps:
1. Download offline upgrade Package: http://download.bt.cn/install/update/LinuxPanel-7.4.3.zip
2. Upload the upgrade package to the /root directory in the server
3. Unzip the file: unzip LinuxPanel-7.4.3.zip
4. Switch to the upgrade package directory: cd panel
5. Execute the upgrade script: bash update.sh
6 , Delete the upgrade package: cd .. && rm -f LinuxPanel-7.4.3.zip && rm -rf panel
Users of Windows version 6.8 update to the following version
Windows official version 6.9.0 (security version)
Update log:
1. Urgent correction of a security risk
This update is an emergency security update. Users of version 6.8 must update to the latest version.
The penalty for damaging a computer is extremely severe, do not try to take advantage of the law:
We have reported this security risk to the local public security bureau. Please do not teach others how to use or use these tools online. Destroying other people's servers, teaching, and operating are all violations of criminal law. Outside of the Internet, the country severely cracks down on the crime of destroying computer information systems, and the sentences are relatively severe. Don't try to break the law. Some users are also affected by this security risk. We will fully cooperate with users to secure evidence and cooperate with the public security organs in the next step of investigation. Affected users, or users who suspect they are affected, can contact us directly. We will send additional manpower to follow up on after-sales service in the near future. If your data is affected and you have no backup, you can contact us to try to restore it through the panel binary log.
The above is the detailed content of Major security breach of pagoda panel! Webmaster needs urgent security updates (with plan). For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

This article provides a troubleshooting guide for BT Panel crashes. It addresses common causes, including resource exhaustion, software conflicts, and database issues. Solutions range from checking server resources and logs to reinstalling BT Panel

This article explains the "502 Bad Gateway" error in BT Panel, highlighting causes like server overload, PHP-FPM issues, database problems, and misconfigurations. Troubleshooting steps and preventative measures, including server monitorin

This article guides users on configuring reverse proxies in BT Panel, covering setup, multi-domain handling, security implications (benefits & risks), and troubleshooting. It details the process of setting up virtual hosts, specifying upstream s

This article guides users on configuring firewall rules within BT Panel. It details adding rules to allow/deny traffic based on IP addresses, ports, and protocols, emphasizing best practices like least privilege and regular review. Troubleshooting

This article compares BT Panel's official and Happy Edition releases. The official version prioritizes stability and security via dedicated support and rigorous testing, while the Happy Edition, a community fork, offers potentially faster feature ac

BT Panel domain binding failures stem from DNS misconfigurations, propagation delays, firewall restrictions, or server issues. Troubleshooting involves verifying DNS records, checking propagation, testing server connectivity, examining BT Panel log

This article explains how to configure a reverse proxy (Nginx/Apache) with BT Panel, which lacks a built-in solution. It details the process: installing the proxy, configuring it to route traffic to BT Panel websites, handling multiple domains, and

BT Panel is free, open-source server management software. Costs arise from the underlying server infrastructure (VPS/dedicated server rental) needed to run it, including domain name, SSL certificate, and bandwidth. Pricing depends entirely on the h
