<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>General Knowledge Archives | cPanel</title>
	<atom:link href="https://www.cpanel.net/blog/category/general-knowledge/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cpanel.net/blog/category/general-knowledge/</link>
	<description>Hosting Platform of Choices</description>
	<lastBuildDate>Tue, 23 Dec 2025 02:30:47 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.cpanel.net/wp-content/uploads/2025/07/cropped-android-chrome-512x512-1-32x32.png</url>
	<title>General Knowledge Archives | cPanel</title>
	<link>https://www.cpanel.net/blog/category/general-knowledge/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Hidden Dangers of Using a Fraudulent cPanel License </title>
		<link>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/</link>
					<comments>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Tue, 27 May 2025 16:03:39 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=68657</guid>

					<description><![CDATA[<p>cPanel is one of the most well-known and trusted hosting panels. Its user-friendly interface and powerful tools simplify the management of servers, websites, databases, and more. However, not all cPanel licenses are purchased through legitimate, authorized channels. Sometimes users are led down a risky path: the use of fraudulent or ‘cracked’ cPanel licenses. Here’s how [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/">The Hidden Dangers of Using a Fraudulent cPanel License </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">cPanel is one of the most well-known and trusted hosting panels. Its user-friendly interface and powerful tools simplify the management of servers, websites, databases, and more. However, not all cPanel licenses are purchased through legitimate, authorized channels. Sometimes users are led down a risky path: the use of fraudulent or ‘cracked’ cPanel licenses. Here’s how cPanel itself detects and handles <a href="https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/">fraudulent licenses</a>.</p>



<p class="wp-block-paragraph">The short-term savings hide long-term dangers that can compromise your entire server or website. In this post, we dive deep into the hidden risks associated with using fraudulent cPanel licenses and why the true cost is far higher than the license fee you avoid.&nbsp;</p>



<h2 class="wp-block-heading">Understanding Fraudulent cPanel Licenses&nbsp;</h2>



<p class="wp-block-paragraph">A fraudulent cPanel license is one that has not been legitimately purchased directly from cPanel or an authorized partner. These licenses are often obtained illegally, bypassing the official activation and validation processes.&nbsp;</p>



<p class="wp-block-paragraph">Wondering how users end up with these unlicensed accounts? Often, it&#8217;s through attractive offers for &#8220;cheap cPanel hosting&#8221; or &#8220;cheap cPanel licenses&#8221; advertised on different forums or websites. These sellers might offer what looks like a working cPanel installation, but it&#8217;s built upon an illegal licensing foundation. Sometimes, users might even be unaware that they are receiving an unlicensed product, totally misled by the vendor&#8217;s claims.&nbsp;</p>



<h2 class="wp-block-heading">Hidden Risks and Dangers You Can&#8217;t Afford to Ignore&nbsp;</h2>



<p class="wp-block-paragraph">The consequences of using a fraudulent cPanel license don’t just include a conflict of ethics. Fake licenses pose serious threats to the security, stability, and legality of your servers and websites.&nbsp;</p>



<h2 class="wp-block-heading">Security Vulnerabilities&nbsp;</h2>



<p class="wp-block-paragraph">Fraudulent cPanel licenses are often tampered with. They can have malicious code or backdoors or even be intentionally left unpatched in order to create significant security holes.</p>



<p class="wp-block-paragraph">Hackers actively seek out servers running unlicensed software because they are easy targets. They can use these vulnerabilities to steal sensitive data, infect your server and your visitors with malware, launch phishing attacks, or even take complete control of your server.</p>



<p class="wp-block-paragraph">Want to learn how to protect your server? Check out our <a href="https://docs.cpanel.net/knowledge-base/security/security-best-practices/">cPanel Security Best Practices</a>.</p>



<h2 class="wp-block-heading">Lack of Support&nbsp;</h2>



<p class="wp-block-paragraph">By using a fake license, you’re working outside of the official cPanel ecosystem. This means you are not entitled to any official <a href="https://support.cpanel.net/hc/en-us">support from cPanel</a>.</p>



<p class="wp-block-paragraph">You won’t have access to cPanel’s expert support team, leaving you to diagnose and resolve potentially critical problems by yourself which can lead to extended downtime and a compromised server. If you meet technical issues, bugs, or security threats, you’re on your own.</p>



<h2 class="wp-block-heading">Legal Consequences&nbsp;</h2>



<p class="wp-block-paragraph">Software licenses are legal agreements. Using unlicensed software is a violation of copyright and licensing laws. cPanel actively monitors for fraudulent licenses, and if your server is identified, you could face legal repercussions. This can include significant fines and penalties, and in severe cases, facing legal action that could force your website and services offline.&nbsp;</p>



<h2 class="wp-block-heading">Performance Issues&nbsp;</h2>



<p class="wp-block-paragraph">Non-official licenses might be outdated or improperly optimized. These versions can lack the latest optimizations and updates of official licenses, leading to significant performance problems.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">You might experience slow website loading times, frequent downtime, errors, and crashes. This not only frustrates your users but also harms your online reputation. It can also negatively impact your search engine rankings.&nbsp;</p>



<h2 class="wp-block-heading">The Danger of Fraudster-Operated Update Mirrors&nbsp;</h2>



<p class="wp-block-paragraph">Some providers of fraudulent licenses run their own unofficial update mirrors. This allows servers with fake licenses to seemingly receive updates, giving users a false sense of security. However, these mirrors are not verified or controlled by cPanel.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">The people running them could decide to replace certain packages with their own versions at any time. This means that even when you think you&#8217;re updating your server, you could actually be installing malware or creating new vulnerabilities. These unofficial mirrors expose your server to third-party exploits and put your data at extreme risk.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">How to Identify and Avoid Fraudulent Licenses&nbsp;</h2>



<figure class="wp-block-image size-full"><img decoding="async" src="/wp-content/uploads/2025/05/cPanel_license_verification.png" alt="verify your license form screenshot" class="wp-image-68769"/></figure>



<p class="wp-block-paragraph">There are clear steps you can take to protect yourself:</p>



<ul class="wp-block-list">
<li><strong>Verify your license</strong>: The first step is to <a href="https://verify.cpanel.net/app/verify">verify the authenticity of your cPanel license</a>.</li>



<li><strong>Purchase from official sources</strong>: To avoid the risks altogether, purchase your cPanel license directly from the <a href="https://www.cpanel.net/pricing/">official cPanel website</a> or through an authorized <a href="https://partnernoc.cpanel.net/">cPanel Partner</a>. A list of official partners is available on the cPanel website.</li>



<li><strong>Question “cheap” offers</strong>: Always keep in mind that if a deal seems too good to be true, it probably is. Legitimate cPanel licenses have a standard pricing structure, and big deviations should raise red flags for you at once.</li>
</ul>



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">The short-term savings of using a fraudulent cPanel license are an illusion. They come at the expense of your security, reliability, legal standing, and performance. The hidden dangers and potential consequences just aren’t worth the risk. From critical server and site vulnerabilities to the complete lack of support available if things go wrong, using an unlicensed cPanel account puts your entire online presence in jeopardy.</p>



<p class="wp-block-paragraph">If you are currently using a fraudulent cPanel license, we strongly urge you to <a href="https://cpanel.net/pricing/">switch to a legitimate license</a> as soon as possible. Don’t compromise your online security and reputation for the sake of a “cheap” deal. By buying a legitimate cPanel license you’ll receive the best benefit of all: <strong>total peace of mind</strong>.</p>
<p>The post <a href="https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/">The Hidden Dangers of Using a Fraudulent cPanel License </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How To Increase the PHP Max Upload Size in cPanel®?</title>
		<link>https://www.cpanel.net/blog/tips-and-tricks/how-to-increase-the-php-max-upload-size-in-cpanel/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Thu, 28 Oct 2021 18:30:03 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61861</guid>

					<description><![CDATA[<p>PHP protects server performance by limiting file upload sizes, but the default limit is too low for many modern web applications. You’re likely to encounter this issue when a PHP application displays an error message asking you to increase the PHP max upload file size. There are various ways to increase the upload limit, including [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/how-to-increase-the-php-max-upload-size-in-cpanel/">How To Increase the PHP Max Upload Size in cPanel®?</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">PHP protects server performance by limiting file upload sizes, but the default limit is too low for many modern web applications. You’re likely to encounter this issue when a PHP application displays an error message asking you to increase the PHP max upload file size. There are various ways to increase the upload limit, including editing PHP configuration files directly. In this article, we’ll show you how to adjust PHP upload limits in cPanel &amp; WHM quickly.</p>



<h2 class="wp-block-heading"><strong>What Is “upload_max_filesize” in PHP?</strong></h2>



<p class="wp-block-paragraph">The upload_max_filesize directive is a PHP variable set in the system and local php.ini files and user.ini files. These determine the PHP interpreter’s baseline configuration. As you might expect, upload_max_filesize limits the maximum allowable size of an uploaded file. The PHP default is 2 Megabytes, and you will have to increase it if you want to upload larger files via a PHP web application.</p>



<p class="wp-block-paragraph">You may also have to adjust other directives, including:</p>



<ul class="wp-block-list"><li>post_max_size, which must be larger than upload_max_filesize.</li><li>memory_limit, which should be larger than post_max_size.</li></ul>



<p class="wp-block-paragraph">PHP directive values are expressed in bytes. If you set upload_max_filesize to 1000, the maximum size is 1000 bytes. However, you can also use the shorthand byte values K, M, and G for kilobytes, megabytes, and gigabytes. So, 1000K is 1000 kilobytes and 10G is 10 gigabytes.</p>



<h2 class="wp-block-heading"><strong>How to Increase the PHP Max Upload Size in cPanel?</strong></h2>



<p class="wp-block-paragraph">In cPanel, you can edit PHP directives for locations and domains controlled by your account with the <em>MultiPHP INI Editor</em>, which you will find under <em>Software</em> in the main page menu.</p>



<p class="wp-block-paragraph">Open the <em>MultiPHP INI</em> editor and select a location from the dropdown.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/00-cpanel-php-directive-edit.png" alt="" class="wp-image-61865"/></figure>



<p class="wp-block-paragraph">Scroll to the entry for upload_max_filesize and edit the associated value. Ensure that the value for post_max_size is larger than upload_max_filesize, and click apply at the bottom of the page.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/01-cpanel-php-max-upload.png" alt="" class="wp-image-61869"/></figure>



<h2 class="wp-block-heading"><strong>How to Change the PHP Max Upload Size in WHM?</strong></h2>



<p class="wp-block-paragraph">Whereas cPanel allows you to edit PHP directives in local directories, in WHM you can edit directives in the server’s main php.ini file. This affects all accounts using a particular PHP version.</p>



<p class="wp-block-paragraph">To increase the PHP upload limit in WHM, open <em>MultiPHP INI Editor</em> from the <em>Software</em> section of the sidebar menu. In the dropdown, select a PHP version. PHP versions have independent configurations, so you must edit the max upload variable for all versions you wish to change.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/02-whm-max-php-file-upload.png" alt="" class="wp-image-61873"/></figure>



<p class="wp-block-paragraph">Scroll to upload_max_filesize and edit the adjacent value before clicking <em>Apply</em> at the bottom of the page. Ensure that post_max_size is at least as large.</p>



<p class="wp-block-paragraph">To learn more about editing PHP directives and what the customizable directives do, take a look at the <a href="https://docs.cpanel.net/whm/software/multiphp-ini-editor/" target="_blank" rel="noreferrer noopener">MultiPHP INI Editor for WHM</a> documentation.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord" target="_blank" rel="noreferrer noopener">Discord</a>, the <a href="https://forums.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel" target="_blank" rel="noreferrer noopener">Reddit</a>. Be sure to also follow us on&nbsp;<a href="https://facebook.com/cpanel" target="_blank" rel="noreferrer noopener">Facebook</a>,&nbsp;<a href="https://instagram.com/cpanel" target="_blank" rel="noreferrer noopener">Instagram</a>, and&nbsp;<a href="https://twitter.com/cpanel" target="_blank" rel="noreferrer noopener">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/how-to-increase-the-php-max-upload-size-in-cpanel/">How To Increase the PHP Max Upload Size in cPanel®?</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How To Use Cookie-Free Domains for Faster Website Performance</title>
		<link>https://www.cpanel.net/blog/general-knowledge/how-to-use-cookie-free-domains-for-faster-website-performance/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 25 Aug 2021 17:31:19 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61837</guid>

					<description><![CDATA[<p>Cookies are how websites remember. Without them, they forget you as soon as a page finishes loading. This ability to remember allows you to log in to a content management system or put products in an ecommerce shopping cart. It’s what allows a dynamic CMS like WordPress to personalize web pages. But sites don’t need [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-use-cookie-free-domains-for-faster-website-performance/">How To Use Cookie-Free Domains for Faster Website Performance</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cookies are how websites remember. Without them, they forget you as soon as a page finishes loading. This ability to remember allows you to log in to a content management system or put products in an ecommerce shopping cart. It’s what allows a dynamic CMS like WordPress to personalize web pages. But sites don’t need to include a cookie with every file they serve, and needless cookies increase latency and generate unnecessary network traffic.&nbsp;</p>



<p class="wp-block-paragraph">Cookie-free domains let you separate content that needs a cookie from content that doesn’t, ensuring that your site only serves cookies when it needs to. In this article, we explain how to set up and use a cookie-free domain. We use WordPress as an example, but a similar process works with other content management systems and ecommerce stores.</p>



<h2 class="wp-block-heading"><strong>What Is an HTTP Cookie?</strong></h2>



<p class="wp-block-paragraph">An HTTP cookie is a small piece of data a site sends to a web browser when it first loads a page. The cookie contains a unique identifier the browser stores alongside other information about the site. When the browser loads another page, it sends the identifier with the HTTP request. In this way, the site knows when a series of requests come from the same browser.</p>



<p class="wp-block-paragraph">When logging in to a website, you authenticate with a username and password. If you enter the right credentials, the site sets a cookie so you don’t have to re-enter your credentials every time you load a page. This process is called session management; a series of otherwise independent requests are linked to a session by the cookie.</p>



<p class="wp-block-paragraph">This ability to remember is used in other ways too. The site can send personalized content unique to each visitor; an ecommerce store can, for example, display your recent orders because the cookie links an HTTP request to order data associated with your account in the site’s database. In a more controversial application, advertisers use cookies to track you; they set a cookie, and advertising code across the web uses it to build a profile of the products you might be interested in.</p>



<h2 class="wp-block-heading"><strong>Why Use Cookie-Free Domains?</strong></h2>



<p class="wp-block-paragraph">The web needs cookies, but that doesn’t mean every HTTP request does. For example, when you open a page with embedded images, each one triggers an HTTP request. But images don’t change depending on who loads them, so serving a cookie is a waste of bandwidth. You may want to load different images for different users, but that’s handled in the web page’s HTML. The page needs a cookie; the images don’t.</p>



<p class="wp-block-paragraph">The same is true of other static assets such as JavaScript code and CSS. A page might load dozens or even hundreds of static assets, all with useless cookies attached. The time and bandwidth consumed by unnecessary cookies soon add up.</p>



<p class="wp-block-paragraph">Removing cookies from static assets might seem straightforward, but cookies are controlled at the domain level. You can’t serve assets with and without cookies from the same domain. Instead, you need a cookie-free domain just for static assets.</p>



<p class="wp-block-paragraph">There is one more domain-related wrinkle to consider when setting up a cookie-free domain. Subdomains inherit cookie settings from their top-level domain. If you set cookies for “example.com,” they are also served on “www.example.com” and “blog.example.com,” and so on. So, you can’t host your dynamic content at “example.com” and your static content at “static.example.com.”</p>



<p class="wp-block-paragraph">There are two ways around this:</p>



<ol class="wp-block-list"><li>Use a different domain to host static content.</li><li>Use a subdomain for both the dynamic content and the static content. A typical pattern is to use “www.example.com” for dynamic content and “static.example.com” for static content.</li></ol>



<p class="wp-block-paragraph">In our walk-through of setting up a cookie-free domain, we assume you host your site at a “www” subdomain and intend to host static files at a “static” subdomain.</p>



<h2 class="wp-block-heading"><strong>How to Create a Cookie-Free Domain for WordPress</strong></h2>



<p class="wp-block-paragraph">With cPanel &amp; WHM, creating a cookie-free domain for WordPress is straightforward.</p>



<ol class="wp-block-list"><li>Create a suitable subdomain.</li><li>Redirect the subdomain to serve static content from WordPress’s /wp-content directory.</li><li>Configure WordPress to serve static content from the cookie-free domain.</li></ol>



<h3 class="wp-block-heading"><strong>Create a Cookie-Free Domain in cPanel</strong></h3>



<p class="wp-block-paragraph">Open cPanel and navigate to the <em>Subdomains</em> tool, which you’ll find in the <em>Domains</em> section of the main page.</p>



<p class="wp-block-paragraph">Create a new subdomain of the top-level domain connected to your WordPress site. If your WordPress site is hosted at www.example.com, create a subdomain at “static.example.com” or similar.</p>



<p class="wp-block-paragraph">In the <em>Document Root</em> field, enter your WordPress site’s “wp-content” directory. In this case, the site is hosted in “public_html” so we enter “public_html/wp-content.”</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/00-cpanel-cookie-free-domain.png" alt="" class="wp-image-61841"/></figure>



<h3 class="wp-block-heading"><strong>Configure WordPress to Use the Cookie-Free Domain</strong></h3>



<p class="wp-block-paragraph">We must now tell WordPress to serve static content from the new cookie-free domain. To do this, we’ll add two new directives to the site’s “wp-config.php” file. You can access the file on the command line, but you can also edit WordPress configuration files in cPanel’s <em>File Manager</em>, which you can open from the <em>Files</em> section of the main page menu or directly in <em>WP Toolkit</em>.</p>



<p class="wp-block-paragraph">Select “wp-config.php” and click edit in the toolbar.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/01-wordpress-cookie-free-domain.png" alt="" class="wp-image-61845"/></figure>



<p class="wp-block-paragraph">Add the following lines to the file, with appropriate edits to insert your subdomains</p>



<pre class="wp-block-code"><code>define("WP_CONTENT_URL", "static.example.com");
define("COOKIE_DOMAIN", "www.example.com");</code></pre>



<p class="wp-block-paragraph">Click <em>Save Changes</em>.</p>



<p class="wp-block-paragraph">Finally, we edit the site’s database to redirect existing posts to the new subdomain. Before you complete this step, back up the database with <em>WP Toolkit</em> or the <a href="https://blog.cpanel.com/how-to-back-up-and-restore-mysql-databases-in-cpanel/">manual method we explained here</a>. You are about to edit the database irreversibly. If you get it wrong, your site will no longer function correctly.</p>



<ol class="wp-block-list"><li>Open <em>PhpMySQL</em> from the <em>Database</em> section in the cPanel menu <strong>or</strong> access the database directly from your site’s <em>Database</em> tab in <em>WP Toolkit</em>.</li><li>Select your WordPress site’s database and then its <em>_posts</em> table.</li><li>Click the <em>SQL</em> tab.</li></ol>



<p class="wp-block-paragraph">Enter the following SQL code in the text box. Be sure to edit the URLs to match your subdomains:</p>



<pre class="wp-block-code"><code>UPDATE wp_posts SET post_content = REPLACE(post_content,'www.example.com/wp-content/','static.example.com/')</code></pre>



<p class="wp-block-paragraph">Once you have double-checked the SQL, click <em>Go</em> at the bottom of the page.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/02-cpanel-edit-wordpress-database.png" alt="" class="wp-image-61849"/></figure>



<p class="wp-block-paragraph">That’s it! Static content will now be served from your new cookie-free subdomain, and cookies will continue being served from the “www” subdomain domain.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord" target="_blank" rel="noreferrer noopener">Discord</a>, the <a href="https://forums.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel" target="_blank" rel="noreferrer noopener">Reddit</a>. Be sure to also follow us on <a href="https://facebook.com/cpanel" target="_blank" rel="noreferrer noopener">Facebook</a>, <a href="https://instagram.com/cpanel" target="_blank" rel="noreferrer noopener">Instagram</a>, and <a href="https://twitter.com/cpanel" target="_blank" rel="noreferrer noopener">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-use-cookie-free-domains-for-faster-website-performance/">How To Use Cookie-Free Domains for Faster Website Performance</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Change the Main Shared IP Address on cPanel®</title>
		<link>https://www.cpanel.net/blog/tips-and-tricks/how-to-change-the-main-shared-ip-address-on-cpanel/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 18 Aug 2021 18:39:54 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61889</guid>

					<description><![CDATA[<p>cPanel &amp; WHM’s main shared IP address is used by new shared hosting accounts created on a server. This allows web hosts to create new accounts easily and automates the otherwise complex and time-consuming domain and web server configuration process. But what if you want to change the main shared IP address on your cPanel [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/how-to-change-the-main-shared-ip-address-on-cpanel/">How to Change the Main Shared IP Address on cPanel®</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">cPanel &amp; WHM’s main shared IP address is used by new shared hosting accounts created on a server. This allows web hosts to create new accounts easily and automates the otherwise complex and time-consuming domain and web server configuration process. But what if you want to change the main shared IP address on your cPanel server?</p>



<p class="wp-block-paragraph">In this article, we outline a three-step process for changing a server’s shared IP address. Changing the main shared IP is straightforward, but we assume you would like to add a new IP address, change the primary shared hosting address, and migrate existing shared hosting accounts to the new address. You can complete each of these tasks quickly within cPanel &amp; WHM.</p>



<p class="wp-block-paragraph">To follow along, you need root access to a server managed with cPanel &amp; WHM—we’ll be working in the WHM server administration interface. We’ll focus on IPv4 addresses, but a similar process also works for IPv6 addresses.</p>



<h2 class="wp-block-heading"><strong>How to Add a New IP Address to Your Server</strong></h2>



<p class="wp-block-paragraph">First, you will need to arrange for a new IP address with your hosting provider. They will supply an IP from their available address space and configure their network to connect it to your server. In addition to the IP address, you also need the network’s subnet mask. Subnet masks depend on the network’s configuration, so you may have to ask your hosting provider which to use.</p>



<p class="wp-block-paragraph">Once you have a new IP address, you can configure your server to use it with WHM’s <em>‌Add a New IP Address</em> tool, which you will find under <em>IP Functions</em> in the WHM sidebar menu.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/00-cpanel-add-new-IP-address.png" alt="" class="wp-image-61893"/></figure>



<p class="wp-block-paragraph">For more information about adding a new IP address, see <a href="https://blog.cpanel.com/how-to-redirect-an-ip-to-a-domain-configure-domain-redirects-in-cpanel/" target="_blank" rel="noreferrer noopener">How To Redirect An IP To A Domain &amp; Configure Domain Redirects In cPanel</a>.</p>



<h2 class="wp-block-heading"><strong>How to Change Main Shared IP Address</strong></h2>



<p class="wp-block-paragraph">Now that your new IP address is available for use within cPanel &amp; WHM, the next step is to change the main shared IP address. The new address will be used when you create cPanel accounts in the future. Changing the IP address doesn’t migrate existing shared hosting accounts, but we’ll explain how to do that in the next section.</p>



<p class="wp-block-paragraph">You can change the shared hosting IP address in WHM’s <em>Basic WebHost Manager Setup</em> tool.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/01-cpanel-change-shared-IP-address.png" alt="" class="wp-image-61897"/></figure>



<p class="wp-block-paragraph">In <em>Basic WebHost Manager Setup</em>, scroll to the <em>Basic Config</em> section. The first entry configures the IP address used when creating new virtual hosts for shared hosting accounts. Enter the new address, scroll to the bottom of the page, and click save.</p>



<p class="wp-block-paragraph">Do not enter an IP address that you have not already added to cPanel with the process we described in the previous section.</p>



<h2 class="wp-block-heading"><strong>Migrate Shared Hosting Accounts to the New IP Address</strong></h2>



<p class="wp-block-paragraph">Migrating cPanel accounts to use the new IP is the most complex of the three stages we’re looking at today. But it’s relatively straightforward with WHM’s <em>IP Migration Wizard</em>. Before we begin, you should be aware that:</p>



<ul class="wp-block-list"><li>You should not add new cPanel accounts during the migration process. If you do, they may not use the new IP address. It’s better to wait until the migration is complete, after which all newly created accounts will use the correct address.</li><li>The full migration process can take up to 48 hours to complete. The server-side changes happen more quickly, but DNS caches across the internet need time to update.</li></ul>



<p class="wp-block-paragraph">Before we begin, it’s worth emphasizing that the <em>IP Migration Wizard</em> does not add new IPs to your server. You should follow the instructions in this article’s first section to add the new IP addresses before migrating cPanel accounts.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/08/02-cpanel-IP-migration-wizard.png" alt="" class="wp-image-61901"/></figure>



<p class="wp-block-paragraph">The <em>IP Migration Wizard</em> will walk you through the migration process step-by-step. You should complete each step and pay close attention to the information the wizard displays, including any error messages.</p>



<p class="wp-block-paragraph">The IP migration steps are as follows:</p>



<ol class="wp-block-list"><li>Enter the new IP address.</li><li>Confirm the changes. WHM displays a list of current IPs mapped to new IPs so you can verify the accounts and domains that are being migrated. Make sure the planned changes are what you expect. If you confirm and wish to reverse the migration later, you can rerun the <em>IP Migration Wizard</em>, but it may take up to 48 hours to return to the previous configuration. You can also download the translation matrix, a list of domains with their new and old IP addresses.</li><li>cPanel implements configuration changes. This includes updating Apache, FTP, and cPanel configuration files. The new IP address is activated, but the old address is retained so domains continue to be accessible while DNS records are updated.</li><li>DNS migration. The DNS zone files are updated. Be sure to note any errors displayed before progressing to the next step.</li><li>DNS propagation. We recommend that you log out of WHM and wait 48 hours while DNS records propagate. When the waiting period is over, log back in and re-open the <em>IP Migration Wizard</em>. If all is well, it will display a message announcing that the migration is complete.</li></ol>



<p class="wp-block-paragraph">You have now changed the main IP address used with shared hosting accounts and migrated existing accounts to the new address. If you intend to continue using the old IP address on the server, there is nothing more you need to do. However, if you want to delete the old IP address, you should follow the instructions in the <a href="https://docs.cpanel.net/whm/ip-functions/ip-migration-wizard/" target="_blank" rel="noreferrer noopener"><em>IP Migration Wizard</em> documentation</a>.</p>



<p class="wp-block-paragraph">If you experience issues connecting to domains using the new IP, ensure that DNS and reverse DNS records are correctly configured. You can check DNS records in WHM’s <em>DNS Zone Manager</em>. You may need to contact your hosting provider for help with reverse DNS configurations.As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord" target="_blank" rel="noreferrer noopener">Discord</a>, the <a href="https://forums.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel" target="_blank" rel="noreferrer noopener">Reddit</a>. Be sure to also follow us on&nbsp;<a href="https://facebook.com/cpanel" target="_blank" rel="noreferrer noopener">Facebook</a>,&nbsp;<a href="https://instagram.com/cpanel" target="_blank" rel="noreferrer noopener">Instagram</a>, and&nbsp;<a href="https://twitter.com/cpanel" target="_blank" rel="noreferrer noopener">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/how-to-change-the-main-shared-ip-address-on-cpanel/">How to Change the Main Shared IP Address on cPanel®</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How To Manually Remove Malware From Websites</title>
		<link>https://www.cpanel.net/blog/general-knowledge/how-to-manually-remove-malware-from-websites/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Thu, 12 Aug 2021 16:03:05 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61745</guid>

					<description><![CDATA[<p>Your website has been compromised, and you suspect the attackers have injected malware into its code. What can you do about it? There are many ways to approach a malware infection, and we’ll look at some in a moment, but your final recourse may be to roll up your sleeves, hunt through the site’s files, [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-manually-remove-malware-from-websites/">How To Manually Remove Malware From Websites</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Your website has been compromised, and you suspect the attackers have injected malware into its code. What can you do about it? There are many ways to approach a malware infection, and we’ll look at some in a moment, but your final recourse may be to roll up your sleeves, hunt through the site’s files, and remove the malware manually.</p>



<p class="wp-block-paragraph">This article will show you how to find malware code in your site’s files and remove it, using a WordPress site as an example. You don’t have to be a developer to follow along, but you’ll be better able to identify malware if you have some familiarity with coding and the language the site is written in; PHP in WordPress’s case.&nbsp;</p>



<h2 class="wp-block-heading"><strong>How To Avoid Manually Removing Malware from Websites</strong></h2>



<p class="wp-block-paragraph">In an ideal world, you wouldn’t have to remove malware manually. It can be a tedious process, especially if you can’t distinguish between malware and innocent code your site relies on. It’s also easy to miss malware code—online criminals are sneaky, and they go to great lengths to hide it. Unfortunately, you might spend hours hunting down and deleting malware traces, only for a hidden backdoor to reinfect the site immediately.</p>



<p class="wp-block-paragraph">The best option is to avoid malware infection in the first place. Make sure your site is updated, and turn on automatic updates if possible.&nbsp; Be careful when installing plugins and themes, and avoid nulled or pirate software at all costs; it is invariably loaded with malicious code.&nbsp;</p>



<p class="wp-block-paragraph">Automatic malware detection and removal is also less demanding than manual malware removal. cPanel &amp; WHM supports the excellent free <a href="https://docs.cpanel.net/knowledge-base/third-party/how-to-install-imunifyav/">ImmunifyAV scanner</a>, which you can install via WHM’s <em>Security Center</em>. It alerts you when it finds a suspected malware infection and tells you where it is. If you upgrade to ImunifyAV+, you’ll be able to remove malware with the click of a button too.&nbsp;</p>



<p class="wp-block-paragraph">Finally, if you suspect an infection, you should attempt to restore a recent clean backup. Restoring from an uninfected backup overwrites malicious files with clean originals. cPanel’s <a href="https://docs.cpanel.net/knowledge-base/cpanel-developed-plugins/wordpress-toolkit/"><em>WP Toolkit</em></a><em> </em>makes it easy to back up WordPress sites in seconds, or you could use one of the many WordPress plugins that offer backup functionality.&nbsp;</p>



<p class="wp-block-paragraph">If you don’t have a recent backup, then you’ll have to dig in and replace infected files manually.&nbsp;</p>



<h2 class="wp-block-heading"><strong>Manually Removing Malware from a WordPress Site</strong></h2>



<p class="wp-block-paragraph">We’re using WordPress in our walkthrough because it’s the most popular CMS, but a similar process works just as well on other content management systems and ecommerce stores.</p>



<p class="wp-block-paragraph">It should be mentioned that we’re making a big assumption in this article. We’re hoping the malicious code is limited to your website and that the attacker hasn’t gained access to your web hosting server. However, if the server is compromised, the attacker may have replaced system binaries with rootkits and other malware. If that’s happened, you can’t trust any software on the server, including the software we’re about to use to clean malicious code from the site.&nbsp;</p>



<p class="wp-block-paragraph">Before tackling malware removal on WordPress, you should:</p>



<ul class="wp-block-list"><li><strong>Take the site offline. </strong>If possible, use WP Toolkit’s maintenance mode to avoid exposing users to further risk.&nbsp;</li><li><strong>Make a backup. </strong>Back up your site whenever you make changes to its code or database.&nbsp;</li><li><strong>Turn on debug settings. </strong>Debug settings allow WordPress to print error messages to the screen. They’ll help you to figure out what went wrong if you make changes that break the site. You can read more about debug settings and maintenance mode in <a href="https://blog.cpanel.com/wordpress-debugging-with-cpanel-and-wordpress-toolkit/">WordPress® Debugging with cPanel and WP Toolkit</a>.</li></ul>



<p class="wp-block-paragraph">First, we’ll check to see if any files have been modified in the last few days. Most WordPress files are not frequently modified except for static assets like images, so recent changes are a helpful clue.&nbsp;</p>



<p class="wp-block-paragraph">Log in to your server via SSH or open the cPanel <em>Terminal </em>and navigate to the infected site’s directory. You’ll find the Terminal under <em>Advanced </em>in the cPanel main page menu. Your WordPress site is most likely in <em>public_html </em>or a directory inside <em>public_html.</em></p>



<p class="wp-block-paragraph">Run the following command:</p>



<pre class="wp-block-code"><code>find . -name '*.ph*' -mtime -7</code></pre>



<p class="wp-block-paragraph">This displays a list of all PHP files modified in the last seven days. WordPress has hundreds of files that might hide malware, but let’s assume that <em>wp-config.php </em>is at the top of your list. Next, we need to look inside to see if there is any sign of malicious code.&nbsp;</p>



<p class="wp-block-paragraph">Open the file in your text editor. If you prefer not to work with command-line text editors, locate the file in cPanel’s <em>File Manager</em>, and click <em>Edit </em>in the menu bar. You’re looking for anything that seems out of place.</p>



<p class="wp-block-paragraph">Keep an eye out for these red flags:</p>



<ul class="wp-block-list"><li><strong>Mismatched coding styles </strong>— the lines of code may be longer, improperly indented, or excessively complex.</li></ul>



<ul class="wp-block-list"><li><strong>Obfuscated code </strong>— code that has been deliberately disguised. It looks like long strings of meaningless letters and numbers. Not all code that looks like this is malicious; you may come across legitimate hashes that match this description, especially in configuration files.&nbsp;</li><li><strong>Strange URLs </strong>— most URLs in your site’s files are related to the site itself. If you see an unusually formatted or excessively long web address, it may link to a server under the attacker’s control.&nbsp;</li></ul>



<p class="wp-block-paragraph">For example, if you see something like this mixed in with the familiar PHP code, it’s almost certainly malware.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/07/00-remote-wordpress-malware.png" alt="" class="wp-image-61753"/></figure>



<p class="wp-block-paragraph">Most malicious code isn’t that obvious.&nbsp; However, you can compare files with the original to see if anything looks out of place. Download a fresh copy of the same version of WordPress from <a href="https://wordpress.org/download/releases/">WordPress.org</a>. If a plugin or theme file is under suspicion, download a new version from the developer’s site or the WordPress repository.&nbsp;</p>



<p class="wp-block-paragraph">Open your newly downloaded version and compare it to your site’s file. They may not be identical, but you should view any significant differences with suspicion.&nbsp;</p>



<p class="wp-block-paragraph">In many cases, you can simply replace an infected file. Manually clearing malware is a careful process of exchanging infected files for uninfected originals. However, you must be careful not to simply replace files that contain essential configuration data. For example, if you swap <em>wp-config.php </em>for a freshly downloaded file, your site will stop working because that file contains site and database configurations.&nbsp;</p>



<p class="wp-block-paragraph">If you aren’t sure what a file does, check the WordPress documentation to ensure that it is safe to exchange. You may have to copy information from the infected file to its replacement, making sure no malicious code makes its way across.&nbsp;</p>



<p class="wp-block-paragraph">To replace files, use cPanel’s <em>File Manager </em>to delete the infected original and upload the replacement. Then, verify the site still works every time you make a change. If you don’t regularly check and only notice the problem later, you may have no idea which edit did the damage.&nbsp;</p>



<p class="wp-block-paragraph">As we mentioned at the beginning of this article, manual malware removal is a long and tedious process. And there is no guarantee that you’ll find all the malicious code. However, it’s a valuable technique to have under your belt when automatic malware removal and back-ups let you down.&nbsp;As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord">Discord</a>, the <a href="https://forums.cpanel.net/">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel">Reddit</a>. Be sure to also follow us on&nbsp;<a href="https://facebook.com/cpanel">Facebook</a>,&nbsp;<a href="https://instagram.com/cpanel">Instagram</a>, and&nbsp;<a href="https://twitter.com/cpanel">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-manually-remove-malware-from-websites/">How To Manually Remove Malware From Websites</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Manage Inode Quotas and Control Inode Usage</title>
		<link>https://www.cpanel.net/blog/general-knowledge/how-to-manage-inode-quotas-and-control-inode-usage/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 04 Aug 2021 14:21:00 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61693</guid>

					<description><![CDATA[<p>The CentOS operating system has several features that restrict users&#8217; resource consumption. They help web hosts and server administrators to fairly distribute resources on shared servers and to create tiered account systems. Without quotas, rogue users can—accidentally or deliberately—use more than their fair share, hurting their neighbors&#8217; web hosting performance. Inode quotas limit the number [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-manage-inode-quotas-and-control-inode-usage/">How to Manage Inode Quotas and Control Inode Usage</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The CentOS operating system has several features that restrict users&#8217; resource consumption. They help web hosts and server administrators to fairly distribute resources on shared servers and to create tiered account systems. Without quotas, rogue users can—accidentally or deliberately—use more than their fair share, hurting their neighbors&#8217; web hosting performance.</p>



<p class="wp-block-paragraph">Inode quotas limit the number of files a user can create. In this article, we explore what inodes are, how to display inode quotas in cPanel, how to create inode quotas on the command line, how to automate quotas with cPanel &amp; WHM’s standard hooks system.</p>



<h2 class="wp-block-heading"><strong>What Are Inodes?</strong></h2>



<p class="wp-block-paragraph">Inode is short for index node, the filesystem metadata that stores information about each file and where it is. Every file and directory has an inode that contains ownership details, permissions, the file’s size, the filetype, and pointers to its data. The contents and structure differ by filesystem, but inodes play a similar role in all Unix filesystems.</p>



<p class="wp-block-paragraph">Because every file has an inode, enforcing an inode quota is the same as enforcing a limit on the number of files. Inode quotas don’t control the amount of data a user can store in their home directory; they put an upper limit on the number of files, not the size.</p>



<p class="wp-block-paragraph">In the past, inode quotas were essential because each filesystem had a fixed quantity determined when the disk volume was formatted. If users generated too many files, they could use all the inodes, making it impossible to create new files. This was a common occurrence on email servers with inboxes that contain many small files. However, beginning with CentOS 7’s release in 2014, the default filesystem is XFS, which allocates inodes dynamically—you can’t run out of inodes.</p>



<p class="wp-block-paragraph">However, large numbers of files create other problems. They can degrade hard drive performance and increase memory consumption. Additionally, each inode consumes a small amount of disk space, by default 512 bytes on XFS. In rare circumstances, a user could generate so many files they fill the volume with inodes, leaving no space for data. This usually only happens when buggy scripts autogenerate billions of tiny or empty files, but it’s a risk that should be guarded against.</p>



<h2 class="wp-block-heading"><strong>Displaying Inode Usage In cPanel</strong></h2>



<p class="wp-block-paragraph">You can inform cPanel users of their inode limits with the Statistics sidebar’s File Usage feature. It displays both used inodes and available inodes, allowing users to manage file numbers when they approach their limit.</p>



<p class="wp-block-paragraph">The File Usage feature isn’t displayed by default, but server administrators can activate it in WHM. Select <em>Tweak Settings</em> under <em>Server Configuration</em> in the WHM sidebar menu. Enter “inode” in the search box, and activate the <em>Display File Usage information in the cPanel stats bar (inode count)</em> tweak.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/07/00-cpanel-inode-display.png" alt="" class="wp-image-61697"/></figure>



<h2 class="wp-block-heading"><strong>Reducing Inode Usage</strong></h2>



<p class="wp-block-paragraph">cPanel users approaching their inode quota limit can free inodes by deleting files. There are two types of inode quota: soft and hard. If you exceed your soft quota, you will still be able to create files. If you exceed your hard quota, you will not. Many of your hosting account’s features need to generate files. If you hit the hard limit, you won’t be able to add new web pages, receive emails, install software, or many other common tasks.</p>



<p class="wp-block-paragraph">It’s better to reduce inode usage by deleting files long before you hit the hard limit. You can remove files by:</p>



<ul class="wp-block-list"><li>Deleting unused files from your hard drive with the cPanel <em>File Manager</em>.</li><li>Deleting or archiving emails.</li><li>Removing old backups.</li><li>Clearing content management system and web server caches. Caches tend to create lots of small files.</li></ul>



<h2 class="wp-block-heading"><strong>Creating Inode Quotas for XFS Filesystems</strong></h2>



<p class="wp-block-paragraph">cPanel &amp; WHM does not include an inode management interface, but server administrators can use the operating system’s built-in tools to assign user quotas.</p>



<p class="wp-block-paragraph">To use inode quotas, the filesystem must be mounted with the “userquota”, “uqouta”, or “quota” option. To verify quotas are activated and enforced, open the WHM Terminal interface and run the following command:</p>



<pre class="wp-block-code"><code>less /etc/fstab</code></pre>



<p class="wp-block-paragraph">This displays the filesystem configuration options. Find the XFS filesystem you want to apply quotas to, and verify that one of the options we listed above is present. Quotas are activated by default on cPanel servers, so they should already be configured.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/07/01-cpanel-inode-quota-fstab.png" alt="" class="wp-image-61701"/></figure>



<p class="wp-block-paragraph">Here we can see that the volume mounted on root has the uquota option, which means it’s ready to enforce inode quotas. If you don’t see a similar option, you will have to enable quotas with WHM’s <em>Initial Quota Setup</em> feature.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/07/02-whm-initial-quota-setup.png" alt="" class="wp-image-61705"/></figure>



<p class="wp-block-paragraph">In WHM, navigate to <em>Server Configuration</em> -&gt; <em>Initial Quota Setup</em>. Click the proceed button. Depending on the filesystem’s size, enabling quotas may take some time. Once they are enabled, you must reboot the server.</p>



<p class="wp-block-paragraph">If you prefer to activate quotas on the command line, you can run the following commands as root:</p>



<pre class="wp-block-code"><code>/scripts/initquotas
/scripts/fixquotas
reboot</code></pre>



<p class="wp-block-paragraph">To verify that quotas are active, rerun the “less /etc/fstab” command and check that the relevant volumes now have the quota option as discussed above.</p>



<p class="wp-block-paragraph">Next, we have to apply a quota to a user. To do so, we use the “xfs_quota” command as root:</p>



<pre class="wp-block-code"><code>xfs_quota -x -c 'limit -u isoft=100000 ihard=150000 cpanel1' /</code></pre>



<p class="wp-block-paragraph"><br>This command gives the user “cpanel1” a soft limit of 100,000 inodes and a hard limit of 150,000 inodes on the filesystem mounted at “/”. In a real-world hosting scenario, you are unlikely to use the “/” partition for user data, so ensure that you exchange the “/” for the correct mount point of your filesystem.</p>



<p class="wp-block-paragraph">Once the inode quotas are set, the cPanel user will now be able to see the limit in their Statistics sidebar’s File Usage section. It displays the soft limit and consumed inodes as a percentage.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/07/03-inode-quota-display.png" alt="" class="wp-image-61709"/></figure>



<h2 class="wp-block-heading"><strong>Automating Inode Quotas</strong></h2>



<p class="wp-block-paragraph">The manual method is fine for a handful of users, but it would soon get tiresome on a busy shared hosting server. That’s why cPanel provides standardized hooks that can trigger scripts when cPanel &amp; WHM performs an action, such as creating a new hosting account. Using hooks and custom code, you can automatically apply inode and other quotas when accounts are created or when dozens of other events occur.</p>



<p class="wp-block-paragraph">Hooks can trigger Perl modules and scripts, PHP scripts, and shell scripts. We describe the process of creating a simple shell script and registering it with a hook in <a href="https://support.cpanel.net/hc/en-us/articles/360037044953-How-to-Setup-Standardized-Hooks-with-BASH-in-cPanel-WHM" target="_blank" rel="noreferrer noopener"><em>How to Setup Standardized Hooks with BASH in cPanel &amp; WHM</em></a>. For more complex functionality, we recommend writing a Perl module, which will have access to variables in the cPanel environment. You can find more information in our <a href="https://documentation.cpanel.net/display/DD/Guide+to+Standardized+Hooks" target="_blank" rel="noreferrer noopener"><em>Guide to Standardized Hooks</em></a>.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord">Discord</a>, the <a href="https://forums.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel" target="_blank" rel="noreferrer noopener">Reddit</a>. Be sure to also follow us on&nbsp;<a href="https://facebook.com/cpanel" target="_blank" rel="noreferrer noopener">Facebook</a>,&nbsp;<a href="https://instagram.com/cpanel" target="_blank" rel="noreferrer noopener">Instagram</a>, and&nbsp;<a href="https://twitter.com/cpanel">T</a><a href="https://twitter.com/cpanel" target="_blank" rel="noreferrer noopener">witter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/how-to-manage-inode-quotas-and-control-inode-usage/">How to Manage Inode Quotas and Control Inode Usage</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is a Yat? Emoji Identifiers Explained</title>
		<link>https://www.cpanel.net/blog/general-knowledge/what-is-a-yat-emoji-identifiers-explained/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 28 Jul 2021 19:46:00 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61673</guid>

					<description><![CDATA[<p>Many of the most complex systems on the web deal with naming and identity verification. If you manage a website, you’re already familiar with web URLs, IP addresses, signed SSL certificates, and perhaps cryptocurrency addresses. But what if you could have a single name that links to all of your online identities, an identifier that [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-a-yat-emoji-identifiers-explained/">What is a Yat? Emoji Identifiers Explained</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Many of the most complex systems on the web deal with naming and identity verification. If you manage a website, you’re already familiar with web URLs, IP addresses, signed SSL certificates, and perhaps cryptocurrency addresses. But what if you could have a single name that links to all of your online identities, an identifier that is uniquely yours and tied to your social media handles and domain names? And what if, instead of web addresses and numbers, your identifier looked something like this: <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f30a.png" alt="🌊" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f373.png" alt="🍳" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f418.png" alt="🐘" class="wp-smiley" style="height: 1em; max-height: 1em;" />?</p>



<p class="wp-block-paragraph">That’s the goal of a new online naming system called <a href="https://waitlist.y.at/" target="_blank" rel="noreferrer noopener">Yat</a>. A yat is a string of up to six emoji that form an emoji identifier. Each is unique, and users can connect their yat to data associated with their online identity. You might link your Yat address to social media handles or your website, but Yat also supports other data types, including cryptocurrency addresses and even arbitrary chunks of text.</p>



<p class="wp-block-paragraph">The Yat team aims to create an easy-to-use, universal, and instantly recognizable online name. Users choose the emoji that best express their identity, and they can use that uniquely personal symbol anywhere on the web.</p>



<h2 class="wp-block-heading"><strong>How Do Yats Work?</strong></h2>



<p class="wp-block-paragraph">Yat is a company that develops the software and infrastructure to support Yat emoji identifiers. Yat is not the first implementation of this idea. You can also use emoji-based identifiers on the Ethereum blockchain with the <a href="https://ens.domains/" target="_blank" rel="noreferrer noopener">Ethereum Name Service</a>. But Ethereum-backed emoji identifiers are complicated to set up and use. In contrast, Yat aims to simplify the user experience so people who aren’t steeped in crypto culture and blockchain technology can take advantage of emoji identifiers.</p>



<p class="wp-block-paragraph">Yats are based on a <a href="https://api-docs.y.at/docs/overview" target="_blank" rel="noreferrer noopener">key-value database</a>. The Yat is the key, and the values are emoji ID records, which can include many different record categories. We’ve already mentioned some of them, but the complete list, which is likely to grow, includes:</p>



<ul class="wp-block-list"><li>Website URLs</li><li>Social media handles</li><li>Cryptocurrency addresses</li><li>Payment rail handles</li><li>Locations</li><li>Email addresses</li><li>Domain name system fields</li><li>Arbitrary text data</li></ul>



<p class="wp-block-paragraph">The domain name system fields may be of particular interest to cPanel &amp; WHM users. Yat supports a comprehensive range of DNS records, including A records, CNAMEs, and mail exchange (MX) records. In theory, that means Yat could replace some aspects of the domain name system, similar to the decentralized domain names <a href="https://blog.cpanel.com/what-is-a-decentralized-domain-name-system/" target="_blank" rel="noreferrer noopener">we discussed in an earlier article</a>. However, the centralized infrastructure hosted at the y.at domain only supports simple redirects. Yat is an early-stage alpha project, and its infrastructure doesn’t yet match the project’s ambitions.</p>



<h2 class="wp-block-heading"><strong>Are YATs NFTs?</strong></h2>



<p class="wp-block-paragraph">If you’re interested in blockchain technology, you’ll have noticed that we haven’t talked about how Yats are implemented. They seem an ideal application for a blockchain distributed ledger. However, the current implementation is not based on a blockchain. The key-value store uses a Merkle tree data structure stored on centralized infrastructure managed by the Yat business.</p>



<p class="wp-block-paragraph">We discussed using blockchains to store and manage identifiers at length in <em><a href="https://blog.cpanel.com/what-is-a-decentralized-domain-name-system/" target="_blank" rel="noreferrer noopener">What Is a Decentralized Domain Name System?</a></em> As a decentralized, distributed, and tamper-proof public ledger, blockchains store identifiers and associated data in a system that doesn’t depend on a single company’s infrastructure and intentions. As with NFTs, which we explored in <em><a href="https://blog.cpanel.com/what-is-an-nft-non-fungible-tokens-explained/" target="_blank" rel="noreferrer noopener">What Is an NFT? Non-Fungible Tokens Explained</a></em>, a blockchain could also support a reliable market in emoji identifiers, allowing for their sale and transfer.</p>



<p class="wp-block-paragraph">At the time of writing, Yats have none of these qualities. The infrastructure is not distributed, and the database is not publicly verifiable. Yats cannot be transferred; in fact, the <a href="https://pre-waitlist.y.at/terms" target="_blank" rel="noreferrer noopener">terms of service</a> forbid selling or otherwise transferring emoji identifiers.</p>



<p class="wp-block-paragraph">However, Yat emoji identifiers are in a very early stage of development, and the team is working to transition to a <a href="https://www.tari.com/" target="_blank" rel="noreferrer noopener">Tari blockchain</a>. Tari is a digital-asset-focused blockchain protocol designed to allow users to register, purchase, and transfer assets such as event tickets and emoji identifiers.</p>



<h2 class="wp-block-heading"><strong>How to Get a Yat Emoji Identifier</strong></h2>



<p class="wp-block-paragraph">As an early alpha product, yats are not yet publicly available. To register a Yat, you’ll need an invite code, which you can get from a user who has codes to spare or by joining the waitlist on <a href="https://waitlist.y.at/">y.at</a>.</p>



<p class="wp-block-paragraph">In April, Yat <a href="https://destiny.y.at/">ran an auction</a> to sell a selection of the most desirable emoji identifiers, including single and double emoji strings. The auction was a success, with some identifiers achieving six-figure bids. For example, <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f680.png" alt="🚀" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f315.png" alt="🌕" class="wp-smiley" style="height: 1em; max-height: 1em;" /> sold for $200,000 and <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f411.png" alt="🐑" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f459.png" alt="👙" class="wp-smiley" style="height: 1em; max-height: 1em;" />—lamb bikini, advertised as the Lamborghini yat—sold for $60,000. The highest-priced to date was the golden key (<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f511.png" alt="🔑" class="wp-smiley" style="height: 1em; max-height: 1em;" /> ), which went for a staggering $450,000. Future auctions are likely and may be your best option if you want a short and desirable yat.</p>



<p class="wp-block-paragraph">However, it’s worth remembering that people are bidding in the expectation that yats will become a salable commodity when they transfer to the Tari blockchain. It’s an effort to establish a market similar to the one that already exists for NFTs. As we mentioned above, yats are not yet based on a blockchain and can’t currently be sold.</p>



<p class="wp-block-paragraph">If you’re tempted to join the waitlist, there’s one other limitation of which you should be aware. Some emoji can’t be used in a yat. Technical limitations and security issues mean you’ll have to choose from an approved list. You can’t use country flags because they’re difficult to distinguish and might be used in phishing attacks. The same is true for emoji with multiple color variations, such as the <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2764.png" alt="❤" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f499.png" alt="💙" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f49c.png" alt="💜" class="wp-smiley" style="height: 1em; max-height: 1em;" /> heart emoji. Only the red heart can appear in a yat. Perhaps most unfortunately, Yat doesn’t support modifiable emoji, including gender or race modifiers.</p>



<p class="wp-block-paragraph">Yat is a fascinating variation on online identifiers, particularly its goal of creating an emoji identifier ecosystem non-technical people can use to create expressive and universally recognizable names. However, it will be some time before Yat migrates to a blockchain and fulfills the system’s early promise.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord" target="_blank" rel="noreferrer noopener">Discord</a>, the <a href="https://forums.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel" target="_blank" rel="noreferrer noopener">Reddit</a>. Be sure to also follow us on&nbsp;<a href="https://facebook.com/cpanel" target="_blank" rel="noreferrer noopener">Facebook</a>,&nbsp;<a href="https://instagram.com/cpanel" target="_blank" rel="noreferrer noopener">Instagram</a>, and&nbsp;<a href="https://twitter.com/cpanel">T</a><a href="https://twitter.com/cpanel" target="_blank" rel="noreferrer noopener">witter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-a-yat-emoji-identifiers-explained/">What is a Yat? Emoji Identifiers Explained</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Secure Your cPanel Server With SSH Keys And Public Key Cryptography</title>
		<link>https://www.cpanel.net/blog/tips-and-tricks/secure-your-cpanel-server-with-ssh-keys-and-public-key-cryptography/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 09 Jun 2021 20:45:00 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61237</guid>

					<description><![CDATA[<p>cPanel &amp; WHM is a complete server management solution, but you may occasionally need to log in to your server&#8217;s shell to run scripts or edit configuration options on the command line. The most secure way to remotely log in is with SSH. An SSH client on your local computer connects to a daemon on [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/secure-your-cpanel-server-with-ssh-keys-and-public-key-cryptography/">Secure Your cPanel Server With SSH Keys And Public Key Cryptography</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">cPanel &amp; WHM is a complete server management solution, but you may occasionally need to log in to your server&#8217;s shell to run scripts or edit configuration options on the command line. The most secure way to remotely log in is with SSH. An SSH client on your local computer connects to a daemon on the server. SSH encrypts the commands you send to the server and the information it sends back.</p>



<p class="wp-block-paragraph">When you log in with SSH, you must supply authentication credentials. These are usually your cPanel account’s username and password. However, password-based logins are not as secure as we might like. Users often choose easy-to-guess passwords. Even if they don’t, malicious bots will bombard SSH with brute force and dictionary attacks, consuming the server’s resources.</p>



<p class="wp-block-paragraph">SSH keys are an alternative way to authenticate using public-key cryptography and a pair of cryptographic keys—one public and one private. SSH keys are more secure because they are not vulnerable to guessing attacks. We discussed SSH keys briefly in <a href="https://blog.cpanel.com/how-to-use-putty-ssh-with-cpanel/">How To Use PuTTY SSH With cPanel</a>. In this article, we’ll dig a little deeper into how public key cryptography works, show you how to generate public-private key pairs with cPanel, and how to use them to authenticate with SSH.</p>



<h2 class="wp-block-heading"><strong>What is Public Key Cryptography?</strong></h2>



<p class="wp-block-paragraph">Cryptography is the science of secrecy. Cryptographers design secure communication systems, and encryption is their most important tool. Simply put, encryption scrambles messages so they can’t be read. You start with a message called the plaintext and convert it to nonsense, which is called the ciphertext. Decrypting reverses the process, converting ciphertext back into readable plaintext.</p>



<p class="wp-block-paragraph">Symmetric encryption is the most familiar type. You need two things to encrypt a message: a key and an encryption algorithm. The key is a string of letters and numbers. The algorithm is a set of instructions for combining the key with the plaintext to create the ciphertext. To decrypt the message, you give the same key and the ciphertext to a related algorithm, and it spits out the plaintext. Only someone with the key can decrypt the message.</p>



<p class="wp-block-paragraph">For symmetric encryption to work, the sender and recipient have to share a secret, the key. But what if you want to encrypt a message where there is no shared secret? This is a common need on the internet. For example, I want to send a secret message to a friend. I can encrypt it, but how do I get the key to them? I can’t just send it over the internet because someone spying on my connection could intercept it and decrypt the message too.</p>



<p class="wp-block-paragraph">The solution is public-key cryptography, which is also called asymmetric encryption. With public-key cryptography, we use two keys, a public key and a private key. Only the private key can decrypt messages encrypted with the public key. Only the public key can decrypt messages encrypted with the private key.</p>



<p class="wp-block-paragraph">When I want to send a secret message to my friend, I ask them to send me their public key. I use it to encrypt the message and send them the ciphertext. They use their private key to decrypt it. Provided they keep the private key secret, anyone with the public key can send a message only they can read.</p>



<p class="wp-block-paragraph">Public key cryptography has two significant consequences. The first is that there are no shared secrets. The second is that the person with the private key can prove who they are by decrypting a message. If I encrypt a message that says “hello” with a person’s public key, and they tell me, “You said hello, ” I can be certain they have the private key. It might not be obvious why that matters yet, but it’s the foundation of online security, including HTTPS encryption and SSH keys.</p>



<h2 class="wp-block-heading"><strong>SSH Keys: SSH Authentication with Public Key Cryptography</strong></h2>



<p class="wp-block-paragraph">SSH key authentication uses the mechanism we just described to verify your identity when you want to log in to your server.</p>



<p class="wp-block-paragraph">It works like this:</p>



<ul class="wp-block-list"><li>You create a pair of keys, one public and one private. You upload the public key to the server, and you keep the private key secret on your local computer.</li><li>When you connect to the server with SSH, the client on your computer tells the SSH daemon which public key is yours.</li><li>The server creates a random string of letters and numbers, which it encrypts with your public key and sends to the client.</li><li>The client decrypts the message using the private key. Remember, only your private key can decrypt messages encrypted with your public key.</li><li>The client takes the decrypted message, hashes it, and sends the hash back to the server. A hash is a sort of one-way cryptographic function. The same string always produces the same hash.&nbsp;</li><li>The server now hashes the original message and compares it to the hash sent by the client. If they match, it proves you have the private key and you are authenticated.</li></ul>



<p class="wp-block-paragraph">Provided you keep the private key secret, this method of authentication is reliable and secure. It isn’t vulnerable to brute-force and dictionary attacks. It also helps avoid the problems that arise when users think “pa55word” is an ingenious solution to their password management problems. Of course, all bets are off if the private key is stolen, but that’s a limitation of all authentication mechanisms.</p>



<h2 class="wp-block-heading"><strong>How to Generate Public and Private Keys with cPanel</strong></h2>



<p class="wp-block-paragraph">To use SSH keys, you need a key pair. There are several ways to create key pairs, but one of the easiest is cPanel’s <em>SSH Access</em> tool, which you’ll find in the <em>Security</em> section of cPanel’s main menu.</p>



<ol class="wp-block-list"><li>Open <em>SSH Access</em> and click <em>Manage SSH Keys</em>.</li><li>Click <em>Generate New Key</em>.</li><li>Enter a name for your keys, or you can create a key pair with the default name “id_rsa.”</li><li>Enter a password for an additional layer of security. Be sure to copy the password and store it safely. It won’t be displayed again, and it can’t be recovered.</li><li>Click <em>Generate Key</em> at the bottom of the page.</li></ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/05/00-cpanel-create-ssh-keys.png" alt="" class="wp-image-61265"/></figure>



<p class="wp-block-paragraph">The next step is authorizing the public key so you can use it for SSH authentication.</p>



<ol class="wp-block-list"><li>Return to the <em>Manage SSH Keys</em> interface, as described above.</li><li>Find the key you just created under <em>Public Keys</em>.</li><li>Click <em>Manage</em> and then <em>Authorize</em> on the next page.</li></ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/05/01-cpanel-authorize-public-key.png" alt="" class="wp-image-61273"/></figure>



<p class="wp-block-paragraph">Finally, we have to download the private key to our local machine (see below for Microsoft Windows<sup>®</sup> and PuTTY instructions).</p>



<ol class="wp-block-list"><li>Once again, go to the <em>Manage SSH Keys</em> tool.</li><li>Scroll to the bottom of the page, where you’ll find your <em>Private Keys.</em></li><li>Click <em>View/Download</em> next to the new private key.</li><li>Click the <em>Download Key</em> beneath the text box that displays the key.</li></ol>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blog.cpanel.com/wp-content/uploads/2021/05/02-cpanel-download-ssh-private-key.png" alt="" class="wp-image-61277"/></figure>



<p class="wp-block-paragraph">The private key is downloaded to your browser’s default download folder. You should move it from there to a safe location. If you would like to make it the default key for your local computer’s user, move the file to the following directory on Mac and Linux, replacing “username” with your local computer’s username.</p>



<pre class="wp-block-code"><code>/home/username/.ssh</code></pre>



<p class="wp-block-paragraph">If you use PuTTY on Windows, you must first convert the private key to PuTTY’s native PPK format.</p>



<ol class="wp-block-list"><li>Navigate to your private keys in cPanel as described above and scroll to the bottom of the page.</li><li>Enter the passphrase associated with your key.</li><li>Click the <em>Convert</em> button, and then <em>Download Key</em>.</li><li>You can now select the PPK file when connecting to your server with PuTTY, as we outlined in <a href="https://blog.cpanel.com/how-to-use-putty-ssh-with-cpanel/">How To Use PuTTY SSH With cPanel</a>.</li></ol>



<h2 class="wp-block-heading"><strong>Log in To cPanel Servers with SSH Keys</strong></h2>



<p class="wp-block-paragraph">If you have followed the walkthrough, you now have an authorized public key in place on your server. The private key is stored on your local machine. To use the keys, you simply tell SSH where to find the private key when you open a connection.</p>



<p class="wp-block-paragraph">On Linux and Mac, the terminal command to initiate an SSH connection is:</p>



<pre class="wp-block-code"><code>ssh -i path_to_private_key username@example.com</code></pre>



<p class="wp-block-paragraph">Replace “path_to_private_key” with the location of your new private key. You could omit this option if you stored the key file in the .ssh folder as your default.</p>



<p class="wp-block-paragraph">SSH keys make your server more secure. They prevent poor password choices from exposing your server and its users to unnecessary risk. To further enhance security, server administrators may want to prevent users from logging in with passwords altogether with the <a href="https://docs.cpanel.net/whm/security-center/ssh-password-authorization-tweak/"><em>SSH Password Authorization Tweak</em></a> in WHM’s <em>Security Center</em>.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord">Discord</a>, the <a href="https://forums.cpanel.net/">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel">Reddit</a>. Be sure to also follow us on <a href="https://facebook.com/cpanel">Facebook</a>, <a href="https://instagram.com/cpanel">Instagram</a>, and <a href="https://twitter.com/cpanel">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/tips-and-tricks/secure-your-cpanel-server-with-ssh-keys-and-public-key-cryptography/">Secure Your cPanel Server With SSH Keys And Public Key Cryptography</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Is An NFT? Non-Fungible Tokens Explained</title>
		<link>https://www.cpanel.net/blog/general-knowledge/what-is-an-nft-non-fungible-tokens-explained/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 02 Jun 2021 14:53:00 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61373</guid>

					<description><![CDATA[<p>NFTs (non-fungible tokens) hit the headlines recently when an artist named Beeple sold a digital image collage for $69 million. Depending on your taste in art, you might find Beeple’s image compelling, but would you pay millions for it? After all, you can “own” a copy of Everydays — The First 5000 Days by downloading [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-an-nft-non-fungible-tokens-explained/">What Is An NFT? Non-Fungible Tokens Explained</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">NFTs (non-fungible tokens) hit the headlines recently when an artist named Beeple <a href="https://www.theverge.com/2021/3/11/22325054/beeple-christies-nft-sale-cost-everydays-69-million" target="_blank" rel="noreferrer noopener">sold a digital image collage</a> for $69 million. Depending on your taste in art, you might find Beeple’s image compelling, but would you pay millions for it? After all, you can “own” a copy of <em>Everydays — The First 5000 Days</em> by downloading the <a href="https://www.beeple-crap.com/everydays" target="_blank" rel="noreferrer noopener">constituent images</a> (although you might violate copyright laws). </p>



<p class="wp-block-paragraph">That’s the problem NFTs are intended to solve. The Mona Lisa is worth about a billion dollars, but an exact digital copy is worth next to nothing. What does the canvas and oils original have that the digital copy doesn’t? It’s not information; modern cameras collect more data than your eyes can process. It’s not the painting’s physical material; you could make similar paints and canvas with a bit of research and a few hundred dollars.</p>



<p class="wp-block-paragraph">The Mona Lisa is valuable, in part, because it’s unique. In economic terms, it’s a scarce resource. Scarcity alone doesn’t make something valuable: rocks are unique too. But a scarce item many people want to own, like a well-regarded work of art, creates sky-rocketing values.</p>



<p class="wp-block-paragraph">Digital art is the opposite of unique. It is infinitely reproducible. It’s impossible to tell the original from a copy of a copy of a copy to millions of iterations. That’s a problem for artists, musicians, and other creatives—not to mention collectors and investors who want to create a market in digital assets.&nbsp;</p>



<p class="wp-block-paragraph">NFTs make digital art economically valuable by making it unique. Or, more accurately, by associating it with something that is unique: a non-fungible token, allowing creators to sell the ownership of an item that can be easily replicated. Online creativity dominates our lives, but until NFTs, a digital Mona Lisa was impossible.</p>



<h2 class="wp-block-heading"><strong>What Does Non-Fungible Mean?</strong></h2>



<p class="wp-block-paragraph">Fungibility is a term of art from economics. An asset is fungible if it can be exchanged for another of the same type. Money is fungible. The $20 bill in my wallet is the same as the $20 bill in yours. We could swap bills, and nothing would change. We’d have the same amount of money.</p>



<p class="wp-block-paragraph">Non-fungible assets can’t be exchanged in this way. A house is non-fungible; we could swap houses, but we’d each have something different. The same is true of cars and furniture and many other items. If I borrowed your car and returned a different one, you would have something to say about it—even if the car I gave you was worth the same as the one I borrowed.</p>



<h2 class="wp-block-heading"><strong>What Is an NFT?</strong></h2>



<p class="wp-block-paragraph">An NFT is a non-fungible token, a chunk of data that includes a unique identifier and a record of ownership underwritten by public-key cryptography. They can’t be copied or manipulated, and each token is unique, so it can’t be exchanged for another token in the way money can. However, NFTs can be bought and sold.</p>



<p class="wp-block-paragraph">So far, NFTs sound about as interesting as rocks: unique but not especially desirable. But NFTs have other, more exciting properties. They can be used to certify the ownership of digital assets, such as a work of art. An NFT represents ownership. When someone buys an NFT linked to artwork, they are, in a sense, buying the artwork. The work itself can be copied, but the token and its association are unique.</p>



<p class="wp-block-paragraph">With NFTs, it’s possible to create a market for digital assets. People can support their favorite artists by buying NFTs associated with their works. Collectors and speculators can buy NFTs as an investment. And it’s not just art: any digital asset can be linked to an NFT. Do you want to own your favorite meme? Meme stars like Ermagherd Girl (Maggie Goldenberger) and Scumbag Steve (Blake Boston) turned <a href="https://www.wired.co.uk/article/nft-memes-2010s" target="_blank" rel="noreferrer noopener">internet fame into money</a> by creating and auctioning NFTs.</p>



<h2 class="wp-block-heading"><strong>How Do NFTs Work?</strong></h2>



<p class="wp-block-paragraph">If you’re familiar with Bitcoin and other cryptocurrencies, you may have recognized our description of NFTs. They share many of the same qualities as cryptocurrencies because they are both based on blockchain technology.</p>



<p class="wp-block-paragraph">A blockchain is a digital ledger that records transactions as a series of blocks. Each block includes a cryptographic hash linking it to the previous block. The result is an ever-growing list of cryptographically linked records. Blockchains are distributed across thousands of computers, each with its own copy. Because blockchains are distributed and cryptographically linked, it’s all but impossible to alter the data they contain, making them a reliable way to store transactions without a central authority.</p>



<p class="wp-block-paragraph">Blockchains were initially developed for fungible assets such as cryptocurrencies. But the Ethereum blockchain, among others, also supports tokens that include information about digital assets. When Vignesh Sundaresan—also known as MetaKovan—paid $69 million for Beeple’s digital art, he bought the right to transfer the relevant NFT to his digital wallet to prove he “owns” <em>Everydays — The First 5000 Days</em>.</p>



<h2 class="wp-block-heading"><strong>What Are NFTs Used For?</strong></h2>



<p class="wp-block-paragraph">We’ve already looked at two uses for NFTs, digital arts and memes, but there are many more, from <a href="https://www.cryptokitties.co/" target="_blank" rel="noreferrer noopener">Cryptokitties</a> to <a href="https://nftnyc.medium.com/nikes-dec-2019-patent-reveals-revolutionary-nft-use-a74c115bd0c" target="_blank" rel="noreferrer noopener">Cryptokicks</a>, Nike’s virtual collectibles. Games companies use NFTs for <a href="https://venturebeat.com/2021/02/26/the-deanbeat-how-non-fungible-tokens-nfts-will-change-games/" target="_blank" rel="noreferrer noopener">in-game assets</a>. The musician Grimes sold a <a href="https://niftygateway.com/itemdetail/primary/0x948b3515d81034a3c16d5393c6c155946c93c103/1" target="_blank" rel="noreferrer noopener">50-second video</a> for $388,000. Perhaps most famously, Twitter CEO Jack Dorsey used an NFT to <a href="https://www.reuters.com/article/us-twitter-dorsey-nft-idUSKBN2BE2KJ" target="_blank" rel="noreferrer noopener">sell his first tweet</a> for almost $3 million.</p>



<p class="wp-block-paragraph">How, as a creator, can you get into NFTs? First, you’ll have to figure out how to create one and associate it with a digital asset. Then, you’ll have to choose a blockchain to store your NFT. <a href="https://ethereum.org/en/" target="_blank" rel="noreferrer noopener">Ethereum</a> is the most popular, and the most straightforward way to create an Ethereum wallet is with one of the large cryptocurrency exchange platforms, such as <a href="https://www.coinbase.com/" target="_blank" rel="noreferrer noopener">Coinbase</a>. Finally, you’ll connect your wallet to an Ethereum marketplace such as OpenSea or Rarible, and upload the asset. Most NFTs are sold by auction, but there’s nothing to stop you from selling them directly to buyers.</p>



<p class="wp-block-paragraph">NFTs are a fascinating evolution of both the blockchain and the market in digital arts and collectibles. Currently, the focus is on multi-million dollar headline sales, but NFTs also create a sustainable economy for artists, writers, videographers, and musicians who struggle to monetize their work.</p>



<p class="wp-block-paragraph">As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord">Discord</a>, the <a href="https://forums.cpanel.net/">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel">Reddit</a>. Be sure to also follow us on <a href="https://facebook.com/cpanel">Facebook</a>, <a href="https://instagram.com/cpanel">Instagram</a>, and <a href="https://twitter.com/cpanel">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-an-nft-non-fungible-tokens-explained/">What Is An NFT? Non-Fungible Tokens Explained</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Is a Decentralized Domain Name System?</title>
		<link>https://www.cpanel.net/blog/general-knowledge/what-is-a-decentralized-domain-name-system/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 26 May 2021 17:45:00 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=61293</guid>

					<description><![CDATA[<p>The domain name system (DNS) is a part of the internet’s plumbing users may not often think about unless it stops working. It’s a different story for web hosting providers and site owners; they deal with DNS directly because they depend on it to translate human-friendly web addresses into machine-friendly IP addresses. Every website has [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-a-decentralized-domain-name-system/">What Is a Decentralized Domain Name System?</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The domain name system (DNS) is a part of the internet’s plumbing users may not often think about unless it stops working. It’s a different story for web hosting providers and site owners; they deal with DNS directly because they depend on it to translate human-friendly web addresses into machine-friendly IP addresses.</p>



<p class="wp-block-paragraph">Every website has a domain name registered with a domain name registrar. The registrars work with registry operators, which manage registries—databases of domain and registrant information— and top-level DNS servers. At the root of the tree is IANA, the Internet Assigned Numbers Authority. IANA is administered by ICANN, the Internet Corporation for Assigned Names and Numbers. It maintains the root zone files and delegates domain name management of top-level domains like <em>.com</em> to registry operators.</p>



<p class="wp-block-paragraph">It’s a complicated hierarchy, and for the most part, it works well. There are, however, weaknesses with this system, which was invented in 1983, almost a decade before Tim Berners-Lee published the <a href="http://info.cern.ch/hypertext/WWW/TheProject.html">first website</a>. When top-level DNS servers go down, so do large chunks of the web, which<a href="https://www.forbes.com/sites/daveywinder/2020/07/18/internet-down-human-error-not-cyber-attack-to-blame-says-cloudflare/?sh=2f08a62f78f6"> happens</a> with <a href="https://www.wired.com/story/dns-ddos-amplification-attack/">alarming regularity</a>. The system depends on the trustworthiness of registrars and registry operators, and it’s a weak point criminals and censorious governments can attack.</p>



<p class="wp-block-paragraph">A decentralized domain name system is a possible solution, and blockchain-based DNS looks like the most promising candidate in 2021. Decentralized DNS isn’t in a position to take over from the centralized DNS we’re all familiar with just yet. But it’s worth understanding how it works and the role it could play in bringing resilience and independence to one of the most centralized and hierarchical aspects of the internet’s infrastructure.</p>



<h2 class="wp-block-heading"><strong>How Do Decentralized Domain Name Systems Work?</strong></h2>



<p class="wp-block-paragraph">Decentralized domain name projects aim to remove DNS’s dependence on ICANN and the registries. Blockchains, the technology Bitcoin is based on, are one way to achieve this. A blockchain is a distributed public ledger—a database duplicated across many computers. Blockchains are organized into sequential blocks of data where each block is connected to the previous and subsequent blocks.</p>



<p class="wp-block-paragraph">In the case of Bitcoin, the blockchain acts as a decentralized record of transactions, but it’s easy to see how this could replace some DNS functionality. Instead of registering a domain name with a registrar, you would register it on a blockchain. Because blocks are ordered and the blockchain is distributed, no one can register a name twice, just as they can’t spend the same bitcoin twice.</p>



<p class="wp-block-paragraph">Decentralized DNS systems don’t aim to replace every part of the domain name system. Instead, they act as alternate roots. Much of DNS is already decentralized. Anyone can use cPanel &amp; WHM to set up an authoritative domain name server for their own domains. However, the registries are centralized, and one organization manages the root zone file. That’s why you have to register domain names with a registrar; they’re agents of the central authority. It’s also why you pay regular renewal fees. A centralized global naming system is expensive to run.</p>



<p class="wp-block-paragraph">We’re in the early days of decentralized DNS, and there are several active projects with similar aims. <a href="https://namecoin.org/" target="_blank" rel="noreferrer noopener">Namecoin</a> was one of the first. It was released in 2011 but hasn’t seen widespread adoption. <a href="https://unstoppabledomains.com/" target="_blank" rel="noreferrer noopener">Unstoppable Domains</a> is another entry in the field. <a href="https://handshake.org/" target="_blank" rel="noreferrer noopener">Handshake</a> is an interesting new contender which bills itself as a “decentralized naming and certificate authority.”</p>



<p class="wp-block-paragraph">Like the other decentralized naming systems, Handshake is a blockchain-based root zone alternative with an interesting solution to a problem that plagued earlier efforts—domain squatting. It was easy to register any domain, so squatters gobbled up tens of thousands they never intended to use. Handshake, in contrast, uses an auction to allocate domains. Like Bitcoin, the Handshake blockchain uses a proof-of-work “mining” system to add new blocks, generating a coin called HNS. HNS coins are used to <a href="https://hsd-dev.org/guides/auctions.html" target="_blank" rel="noreferrer noopener">bid in Vickery auctions</a> for top-level domains. For the same reason, Handshake-registered domains do have associated renewal fees.</p>



<h2 class="wp-block-heading"><strong>What’s The Point of Decentralized Domain Names</strong></h2>



<p class="wp-block-paragraph">Decentralization is the primary motivation behind blockchain-based domains, but there are other potential benefits.</p>



<ul class="wp-block-list"><li><strong>Anonymous</strong> — Just as Bitcoin transactions are anonymous, so are blockchain-registered domains.</li><li><strong>Censorship resistant</strong> — A centralized DNS system is vulnerable to censorship. The operating authority could be influenced to remove registered domains from the registry. Blockchains are distributed, and no single entity controls them, making censorship much harder.</li><li><strong>Secure</strong> — You might have noticed that Handbrake also calls itself a “decentralized certificate authority.” Today, we rely on centralized certificate authorities and SSL certificates to verify the identity of sites we connect to. Because they are practically tamper-proof, blockchains can perform the same function. Additionally, CAs can be hacked or subverted, something that’s much harder to achieve on a distributed blockchain.</li></ul>



<p class="wp-block-paragraph">By this point, you might be wondering if you can use a decentralized domain name instead of your website’s current domain. In 2021, not really, especially for business websites. In a problem faced by any newcomer that wants to replace an entrenched system, you’d have to convince users to adopt the new system.</p>



<p class="wp-block-paragraph">Browsers don’t support blockchain DNS unless users add custom DNS servers or resolvers, and nor do email clients and other internet-based applications. As we said at the beginning of this article, users don’t think about DNS until it goes wrong, and most people don’t know what it is. They have little incentive to adopt a new and confusing system.</p>



<p class="wp-block-paragraph">Nevertheless, you can use decentralized domain names alongside the standard system. You can use <a href="https://www.namebase.io/" target="_blank" rel="noreferrer noopener">Namebase</a> to register Handbrake domains and configure DNS records. Unstoppable Domains, which charges for registration but not renewal, can be <a href="https://community.unstoppabledomains.com/t/configure-your-browser-for-unstoppable-domains/1469#heading--chrome" target="_blank" rel="noreferrer noopener">used with Chrome</a> and other modern browsers.As always, if you have any feedback or comments, please let us know. We are here to help in the best ways we can. You’ll find us on <a href="https://go.cpanel.net/discord">Discord</a>, the <a href="https://forums.cpanel.net/">cPanel forums</a>, and <a href="https://reddit.com/r/cpanel">Reddit</a>. Be sure to also follow us on <a href="https://facebook.com/cpanel">Facebook</a>, <a href="https://instagram.com/cpanel">Instagram</a>, and <a href="https://twitter.com/cpanel">Twitter</a>.</p>
<p>The post <a href="https://www.cpanel.net/blog/general-knowledge/what-is-a-decentralized-domain-name-system/">What Is a Decentralized Domain Name System?</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
