/scripts/whoowns domain.com
tail -100 $(ls -dt /usr/local/cpanel/logs/cpbackup/* | head -n1) | grep 'error\|warn'
tail -3 $(ls -dt /usr/local/cpanel/logs/cpbackup/* | head -n1)
echo "Total Accounts to backup: $(grep -Li "suspended" $(grep -l "^BACKUP=1" /var/cpanel/users/*) | wc -l)" && echo "Backed up accounts: $(cd "$(grep "BACKUPDIR" /var/cpanel/backups/config | awk '{print $2}')"/"$(date -dlast-sunday +%Y-%m-%d)"/accounts && ls | wc -l)"
echo -e "\\n~~~~JB accounts backup last job stats~~~\\n" && tail -1 $(find /usr/local/jetapps/var/log/jetbackup/backup/ -type f -size +2k | xargs ls -dt | head -n 1) | awk '{print "Job date:"$1"-"$2" "$3", status: "$7" "$8}' | tr '[' ' ' && echo "Start time:" && head -1 $(find /usr/local/jetapps/var/log/jetbackup/backup/ -type f -size +2k | xargs ls -dt | head -n 1) | awk '{print $4}' | cut -d ':' -f 1,2 | awk '{print $0" AM"}' && echo "End time:" && tail -1 $(find /usr/local/jetapps/var/log/jetbackup/backup/ -type f -size +2k | xargs ls -dt | head -n 1) | awk '{print $4}' | cut -d ':' -f 1,2 && echo ""
head -1 /var/log/exim_mainlog | awk '{print $1}' ; egrep -o 'dovecot_login[^ ]+|dovecot_plain[^ ]+' /var/log/exim_mainlog | cut -f2 -d":" | sort|uniq -c|sort -nk 1 ; tail -1 /var/log/exim_mainlog | awk '{print From $1}'2020-10-25
exigrep [email protected] /var/log/exim_rejectlog*
grep DOMAIN.com /var/log/maillog | grep failed
grep dovecot_login:[email protected] /var/log/exim_mainlog
/scripts/generate_maildirsize --confirm --allaccounts --verbose USERNAME
/scripts/suspendacct USERNAME
/scripts/unsuspendacct USERNAME
ll /var/cpanel/suspended
or
cat /usr/local/apache/conf/includes/account_suspensions.conf
/usr/local/cpanel/bin/autossl_check --user=USERNAME
cd /var/cpanel
mv autossl_queue_cpanel.sqlite autossl_queue_cpanel.sqlite.old
/usr/local/cpanel/bin/autossl_check_cpstore_queue
grep IP-GOES-HERE addon-domain.main-domain-name.extension-ssl_log | grep 503
grep IP-GOES-HERE /var/log/maillog
grep -rle 'IP-GOES-HERE' /usr/local/apache/domlogs/. | uniq
grep "USERNAME" /usr/local/cpanel/logs/error_log
grep USERNAME /usr/local/cpanel/logs/session_log | grep "NEW .*app=cpaneld" | awk "{print $6}" | sort -u | uniq
grep IP-GOES-HERE /usr/local/cpanel/logs/session_log | grep cpanel-user
grep suspend_incoming /usr/local/cpanel/logs/access_log
grep IP-GOES-HERE /usr/local/cpanel/logs/login_log
/var/cpanel/accounting.log
grep IP /usr/local/cpanel/logs/cphulkd.log
/usr/local/cpanel/logs/cphulkd_errors.log
/scripts/cphulkdwhitelist x.x.x.x
/scripts/cphulkdblacklist x.x.x.x
csf -g 8.8.8.8
csf -dr 8.8.8.8
csf -r
grep -ril "hacked by" ./*
find . -mtime -5 -ls
find /home/USERNAME -type f -mmin +120
grep -r USERNAME /karantin/cxscgi/
find . -print | grep -i .php
find /home/USERNAME/*/wp-content/uploads -print | grep -i .php
grep POST /home/USERNAME/access-logs/* | awk '{print $7}' | sort | uniq -c | sort -n
egrep -c '(wp-comments-post.php|wp-login.php|xmlrpc.php)' /usr/local/apache/domlogs/* |grep -v "_log" |sort -t: -nr -k 2 |head -5 |tee /tmp/delete_check |cut -d'/' -f6; for domlog in $(cut -d':' -f1 /tmp/delete_check); do echo; echo $domlog; echo; echo wp-login.php :: $(grep -c wp-login.php $domlog); echo; grep wp-login.php $domlog | cut -d' ' -f1|egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' |sort |uniq -c |sort -nr | head; echo; echo xmlrpc.php :: $(grep -c xmlrpc.php $domlog); echo; grep xmlrpc.php $domlog |cut -d' ' -f1 |egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' |sort |uniq -c |sort -nr | head; echo; echo wp-comments-post.php :: $(grep -c wp-comments-post.php $domlog); echo; grep wp-comments-post.php $domlog |cut -d' ' -f1 |egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' |sort |uniq -c |sort -nr | head; echo; done
tail -n2000 /var/log/exim_mainlog|grep /home/USERNAME/
grep -R "base64_" /home/USERNAME/
grep -lr --include=*.php "eval(base64_decode" .
grep -lr --include=*.php "eval" .
grep -lr --include=*.php "base64" .
maldet -a /path/to/directory
cat /etc/exim.conf |grep smtp_accept_max
php -i | grep libxml