/scripts/whoowns domain.com
tail -100 $(ls -dt /usr/local/cpanel/logs/cpbackup/* | head -n1) | grep 'error|warn'
tail -3 $(ls -dt /usr/local/cpanel/logs/cpbackup/* | head -n1)
echo "Total Accounts to backup:
echo -e "\n~~~~JB accounts backup last job stats~~~\n" && tail -1 $(find /usr/local/jetapps/var/log/jetbackup/backup/ -type f -size +2k | xargs ls -dt | head -n 1) | awk '{print "Job date:"$1"-"$2" "$3", status: "$7" "$8}' | tr '[' ' ' && echo "Start time:" && head -1 $(find /usr/local/jetapps/var/log/jetbackup/backup/ -type f -size +2k | xargs ls -dt | head -n 1) | awk '{print $4}' | cut -d ':' -f 1,2 | awk '{print
head -1 /var/log/exim_mainlog | awk '{print $1}' ; egrep -o 'dovecot_login[^ ]+|dovecot_plain[^ ]+' /var/log/exim_mainlog | cut -f2 -d":" | sort|uniq -c|sort -nk 1 ; tail -1 /var/log/exim_mainlog | awk '{print From $1}'2020-10-25
exigrep [email protected] /var/log/exim_rejectlog*
grep DOMAIN.com /var/log/maillog | grep failed
grep dovecot_login:[email protected] /var/log/exim_mainlog
/scripts/generate_maildirsize --confirm --allaccounts --verbose USERNAME
/scripts/suspendacct USERNAME
/scripts/unsuspendacct USERNAME
ll /var/cpanel/suspended or cat /usr/local/apache/conf/includes/account_suspensions.conf
/usr/local/cpanel/bin/autossl_check --user=USERNAME
cd /var/cpanel mv autossl_queue_cpanel.sqlite autossl_queue_cpanel.sqlite.old /usr/local/cpanel/bin/autossl_check_cpstore_queue
grep IP-GOES-HERE addon-domain.main-domain-name.extension-ssl_log | grep 503
grep IP-GOES-HERE /var/log/maillog
grep -rle 'IP-GOES-HERE' /usr/local/apache/domlogs/. | uniq
grep "USERNAME" /usr/local/cpanel/logs/error_log
grep USERNAME /usr/local/cpanel/logs/session_log | grep "NEW .*app=cpaneld" | awk "{print $6}" | sort -u | uniq
grep IP-GOES-HERE /usr/local/cpanel/logs/session_log | grep cpanel-user
grep suspend_incoming /usr/local/cpanel/logs/access_log
grep IP-GOES-HERE /usr/local/cpanel/logs/login_log
/var/cpanel/accounting.log
grep IP /usr/local/cpanel/logs/cphulkd.log
/usr/local/cpanel/logs/cphulkd_errors.log
/scripts/cphulkdwhitelist x.x.x.x
/scripts/cphulkdblacklist x.x.x.x
csf -g 8.8.8.8
csf -dr 8.8.8.8
csf -r
grep -ril "hacked by" ./*
find . -mtime -5 -ls
find /home/USERNAME -type f -mmin +120
grep -r USERNAME /karantin/cxscgi/
find . -print | grep -i .php
find /home/USERNAME/*/wp-content/uploads -print | grep -i .php
grep POST /home/USERNAME/access-logs/* | awk '{print $7}' | sort | uniq -c | sort -n
egrep -c '(wp-comments-post.php|wp-login.php|xmlrpc.php)' /usr/local/apache/domlogs/* |grep -v "_log" |sort -t: -nr -k 2 |head -5 |tee /tmp/delete_check |cut -d'/' -f6; for domlog in $(cut -d':' -f1 /tmp/delete_check); do echo; echo
tail -n2000 /var/log/exim_mainlog|grep /home/USERNAME/
grep -R "base64_" /home/USERNAME/ grep -lr --include=.php "eval(base64_decode" . grep -lr --include=.php "eval" . grep -lr --include=*.php "base64" .
maldet -a /path/to/directory
cat /etc/exim.conf |grep smtp_accept_max
php -i | grep libxml