Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Lxadmin/Kloxo name change  





2 Security issues  





3 Project history  





4 References  














Kloxo






Български
فارسی
Tiếng Vit

 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


Kloxo
Developer(s)LxCenter
Stable release

6.1.19

Repositorygithub.com/lxcenter/kloxo
Written inPHP
PlatformLinux
TypeControl panel
LicenseAGPL v3
Websitewww.lxcenter.org Edit this on Wikidata

Kloxo (formerly known as Lxadmin) was a free and open-source[1] web hosting control panel for the Red Hat and CentOS Linux distributions.[2] As of October 2017, the project has been unmaintained with a number of unresolved issues, and the project's website is offline.

Kloxo allows the host administrators to run a combination of lighttpd or Apache with djbdnsorBIND, and provides a graphical interface to switch between these programs without losing data. Kloxo Enterprise can transparently move web/mail/dns from one server running Apache to another running lighttpd. It was formerly considered to be a good free alternative to cPanel hosting control panel.

Kloxo comes integrated with Installapp, which is a bundle of approximately 130 web applications that can be installed to the hosted websites. It is supported by Installatron[3] – a third-party application installer (similar to Fantastico) as a plugin.

As of October 2017 the whole LxCenter website appears to be down with only the GitHub repository (and some forks) remaining with the last notable changes being three years old.

Lxadmin/Kloxo name change

[edit]

Due to concerns about the appropriation[clarification needed] of the name (Lxadmin) the name was replaced with Kloxo. There was an outcry from users as the name change involved a complete upgrade of file structures and it was about two weeks before there was an upgrade script for hosting companies.[citation needed]

Security issues

[edit]

In early June 2009, security related blogs and websites posted details of security loopholes in LxAdmin/Kloxo. Around this time, another piece of software created by the same vendor – HyperVM – was rumored to have been exploited in a massive attack at the British VAserv budget webhosting company. Crackers deleted the content of 100,000 hosted websites in one go, after gaining root access to the system. A detailed timeline of these events was posted several months later.


It is widely acknowledged by the hacker(s) and parties involved that the core exploit had to do with the administrator of those VPS's reusing the same password on all installs, and not utilizing the SSL security feature. Experts believe that this led to the transmission of the password in plain text, allowing hackers to sniff and exploit the host.[4]

In early 2012 the message "DO NOT INSTALL THESE APPS. The applications included in InstallApp are outrageously out of date, and contain known and public security vulnerabilities. Enabling this feature on a live server exposes your server and users to serious security flaws" showed prominently at the top of the InstallApp page. This message was still there in January 2014.

In late 2012, a local privilege escalation exploit was found in Kloxo's lxsuexec and lxrestart programs, allowing an attacker to elevate privileges to root.

Project history

[edit]

While Kloxo initially started as a proprietary control panel, Internal issues arose within the company after the death of its CEO.[5][6] It was later announced on July 10, 2009, that Kloxo and HyperVM would be continued in an open source consortium to be formed by Arthur Thornton, Danny Terweij, and S Bhargava. However, on October 25, 2009, Arthur Thornton officially resigned as the lead developer of Kloxo and HyperVM. Following his resignation, the HyperVM and Kloxo source code was officially released to the public. Arthur Thornton resumed his work on Kloxo and HyperVM in the background in mid-February 2010. As of May 2010, he is now back in the public and should soon be back full-time, though not as lead developer. Andre Allen became Project Manager at LxCenter in late February 2010, at the decision of Danny Terweij.

A fork of the project was created by Mustafa Ramadhan, entitled Kloxo_MR. Work was begun in late 2012 to add extra features to the project.

In September 2020, a new fork called Kloxo Next Generation (KloxoNG) was released as an upgrade pathway for existing Kloxo_MR users. KloxoNG is a rebuild of Kloxo_MR using the Fedora Copr build system. Later releases have included bug fixes and added support for PHP 7.4. Future releases will include further bug fixes, upgrades of the core packages and support for EL8 servers.

References

[edit]
  1. ^ "Kloxo". GitHub. 19 March 2022.
  • ^ "Waltern", LxCenter Staff (29 September 2010). "Can i install kloxo on debian vps?". LxCenter Forum. Archived from the original on 27 July 2011. Retrieved 6 November 2010.
  • ^ "Install Installatron on a Kloxo/LxAdmin server". Installatron web site.
  • ^ "Hacker explains attack". 9 June 2009.
  • ^ "Webhost hack wipes out data for 100,000". The Register.
  • ^ "Techie hangs himself in HSR Layout". The Times Of India. 9 June 2009.

  • Retrieved from "https://en.wikipedia.org/w/index.php?title=Kloxo&oldid=1223028729"

    Categories: 
    Web server management software
    Software using the GNU AGPL license
    Free software programmed in PHP
    Hidden categories: 
    Articles with short description
    Short description matches Wikidata
    Wikipedia articles needing clarification from July 2016
    All articles with unsourced statements
    Articles with unsourced statements from July 2016
     



    This page was last edited on 9 May 2024, at 12:48 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki