store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 26, 2013 12:39 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 15 posts ] 
Author Message
 Post subject: critical security plesk issue
Unread postPosted: Mon Mar 05, 2012 11:44 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Guys take a look at this. I just saw it and pushed right away an update to plesk 10.4.4. I hope I don't have problems with the update. It affects all plesk editions except 10.4.4 according to parallels. The best part is that there is no hotfix for plesk 10.3.1 !

http://kb.parallels.com/en/113321

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Mon Mar 05, 2012 1:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Scott and Mike,

Havent you found a any way to filter again using modsecurity plesk panel ?

I miss those times when I could sleep slightly better at night... !

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Mon Mar 05, 2012 3:32 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
it's covered by ASL 3.0.20.
Please see post viewtopic.php?f=8&t=5773


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Mon Mar 05, 2012 7:26 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
Yup! This framework will let us add the WAF to any web based service... and maybe ftp but I didnt spend a lot of time on that.


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Mon Mar 05, 2012 8:39 pm 
Offline
Verified Vendor
Verified Vendor

Joined: Mon Mar 05, 2012 8:36 pm
Posts: 3
Location: Seattle, WA
nobody wrote:
Guys take a look at this. I just saw it and pushed right away an update to plesk 10.4.4. I hope I don't have problems with the update. It affects all plesk editions except 10.4.4 according to parallels. The best part is that there is no hotfix for plesk 10.3.1 !

http://kb.parallels.com/en/113321


Note, this was address for 10.3.1 in MicroUpdate #5 in September 2011 (updates were also issued at that time for 9.5 and 8.6). Further, no base version (e.g. without MU's applied) were vulnerable after 10.4.0 in November 2011.


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 7:02 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
scott wrote:
Yup! This framework will let us add the WAF to any web based service... and maybe ftp but I didnt spend a lot of time on that.


Damn. How did I miss on that ? Fine job once again !

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 9:33 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
For the avoidance of doubt, I assume this is the same issue with Agent that we've discussed viewtopic.php?f=13&t=5731 or is it something different?

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 9:56 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 11:08 am 
Offline
Verified Vendor
Verified Vendor

Joined: Mon Mar 05, 2012 8:36 pm
Posts: 3
Location: Seattle, WA
faris wrote:
For the avoidance of doubt, I assume this is the same issue with Agent that we've discussed http://www.atomicorp.com/forum/viewtopi ... =13&t=5731 or is it something different?


Same issue.


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 11:08 am 
Offline
Verified Vendor
Verified Vendor

Joined: Mon Mar 05, 2012 8:36 pm
Posts: 3
Location: Seattle, WA
faris wrote:
Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.


For 8.6, this issue was resolved via MU#2 - released in September 2011.


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 12:55 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Guys Plesk 10.4.4 works like a charm up till now. Which is a pleasant surprise. Never happened before :P

Blake when will they fix the issue in which you can move customers between ressellers ? This was a major stepback from version 9 to version 10 ...

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Tue Mar 06, 2012 1:04 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Blake@Parallels wrote:
faris wrote:
Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.


For 8.6, this issue was resolved via MU#2 - released in September 2011.


Thank you for update.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Thu Mar 08, 2012 4:11 pm 
Offline
Forum User
Forum User

Joined: Wed Feb 03, 2010 8:14 pm
Posts: 7
Location: Surrey, BC
My 8.6 is patched. I'm Mr Linux/Plesk Newb Question Man today.

1. I also running a 9.3, so I guess I have to update to 9.5.4?

2. In theory should I have any problems upgrading if I updated the PHP to 5.2 using the AtomicCorp repo?

3. Is it safer to install the updates one at a time or can I jump straight to 9.5.4?

Thanks in adavance!


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Thu Mar 08, 2012 4:37 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
1. I would upgrade
2. You never know, each installation/servermight have different settings. Take care of a godd and complete backup
3. I stick with updating plesk over yum. Than i run the autoinstaller to install MU's. If I would go (which I don't do) and do it via webinterface of Plesk I would update one-by-one.
But thats just my opinion.


Top
 Profile  
 
 Post subject: Re: critical security plesk issue
Unread postPosted: Thu Mar 08, 2012 10:17 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Guys. Its the first time that I see great improvement in Plesk after 3 years. Plesk 10.4.4 seems to actually function ! I still seek to find what it has broken, thats good ! :P

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 15 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group