Cloud Flare honestly does not do alot. it actually causes more issues than anything. Really it depends on how your host setup your cpanel through whm. Many of them do really do a minimum which leaves alot of vulnerabilities (ports open that don't need to be, extra processes, insecure application configs for mysql, php etc...). The list is long of possibilities on a standard cpanel install. If you don't have root or WHM access than you will need to work with your host.
Start by doing a search of your http logs for these 2 words htaccess and filemanager
and see if you find any.
|