Search found 435 matches

by prupert
Thu Aug 06, 2015 4:28 pm
Forum: Requests
Topic: Atmail 1.05 for Plesk 9.x
Replies: 18
Views: 35070

Re: Atmail 1.05 for Plesk 9.x

The open source variant of Atmail has been EOL for some years already. Atmail is no longer supported by Plesk.
by prupert
Wed Aug 05, 2015 10:52 am
Forum: Security Alerts
Topic: BIND vulnerability on Centos 6
Replies: 2
Views: 4865

Re: BIND vulnerability on Centos 6

If you use that argument against CR, you should definitely not use the Atomic or ASL repos. ;-) I for one am strongly recommending to enable CR permanently. They are certainly not test builds, and did pass major QA. Most CR packages are just waiting for the next point release. Right now the CR mostl...
by prupert
Tue Aug 04, 2015 9:02 am
Forum: Atomicorp Modsecurity Rules Support
Topic: license via plesk billing
Replies: 4
Views: 11914

Re: license via plesk billing

Yes, Plesk should take care of everything. See the manual about the Web Application Firewall on http://download1.parallels.com/Plesk/Do ... =73383.htm
by prupert
Tue Aug 04, 2015 9:01 am
Forum: Anti-Spam Help and Discussion
Topic: Can't Reject with Postfix and amavisd/clapf
Replies: 8
Views: 13551

Re: Can't Reject with Postfix and amavisd/clapf

I totally agree with you Scott. Amavisd-new does seem to be the best supported option though. I would be happy with something faster and less ugly to manage.

I have looked into postscreen and we reject using the Spamhaus SBL which does help a lot.
by prupert
Wed Jul 22, 2015 9:30 am
Forum: Anti-Spam Help and Discussion
Topic: Clamav with Postfix?
Replies: 3
Views: 11190

Re: Clamav with Postfix?

Amavisd-new is well documented and the software and all requirements are packaged by EPEL. You need to do a little manual configuration, which can simply be automated using a config management tool such as Ansible.

We use Postfix with Amavisd-new exclusively on all Plesk 12 / CentOS 7 machines.
by prupert
Thu Jun 18, 2015 4:44 am
Forum: Control Panel Support Help
Topic: DH, SSL qmail trouble
Replies: 6
Views: 12834

Re: DH, SSL qmail trouble

Newer versions of OpenSSL reject Diffie Hellman groups below 768 bits to prevent a possible downgrade attack. Your mail server is most likely using a weak cipher to connect to another mail server with a weak Diffie Hellman group. Not sure about the correct TLS settings in Qmail for maximum compatibi...
by prupert
Thu May 21, 2015 7:12 pm
Forum: Requests
Topic: proftpd vulnerability
Replies: 4
Views: 12655

Re: proftpd vulnerability

faris wrote:Some posts on the Odin forums indicate the stock version is not vulnerable. But I have not tested personally.
The Plesk stock version of psa-proftpd is not vulnerable indeed.

Code: Select all

ftp> site cpfr /etc/passwd
500 'SITE CPFR' not understood
by prupert
Wed May 06, 2015 4:10 am
Forum: Atomic Protector (formerly ASL)
Topic: Spawned 'httpd' with '/sbin/service httpd restart
Replies: 3
Views: 5402

Re: Spawned 'httpd' with '/sbin/service httpd restart

That means that psmon is restarting httpd because it thinks it is not running. Is httpd running? What does /var/log/httpd/error_log tell you?
by prupert
Thu Apr 16, 2015 5:51 am
Forum: Control Panel Support Help
Topic: nginx, php-fpm and T_WAF in Plesk 12
Replies: 12
Views: 18890

Re: nginx, php-fpm and T_WAF in Plesk 12

Why place a bulky Apache WAF in front of your lean Nginx setup?
by prupert
Tue Apr 14, 2015 9:08 am
Forum: Atomic Protector (formerly ASL)
Topic: Disable cgroups in ASL 4.0.11
Replies: 1
Views: 3668

Disable cgroups in ASL 4.0.11

Hi ASL, Since the ASL 4.0.11 update "/var/asl/bin/cgacct.sh" is run frequently as part of "/etc/cron.d/asl_cg". Also, the process "cgrulesengd" is running and taking a significant amount of CPU cycles. We do not want to use the ASL Rev Limiter. Is it possible to disable...
by prupert
Fri Apr 10, 2015 12:48 pm
Forum: Control Panel Support Help
Topic: Mail disappearing to outlook.com hosted clients
Replies: 1
Views: 8749

Re: Mail disappearing to outlook.com hosted clients

Some tips:

- Manage and check your mail server reputation at Microsoft mail services: https://postmaster.live.com/snds/ipStatus.aspx
- Contact Microsoft regarding mail delivery: https://support.live.com/eform.aspx?pro ... ct=eformts
by prupert
Thu Mar 05, 2015 9:41 pm
Forum: Atomic Protector (formerly ASL)
Topic: clear entire shun list
Replies: 11
Views: 10393

Re: clear entire shun list

That's odd. You may want to report this to ASL support as that should not be happening! That said, I have seen it from time to time (and reported it). Usually the following works for me to clear the "stuck" blocked IP addresses: service asl-firewall restart If that doesn't work: sqlite3 /v...
by prupert
Thu Feb 26, 2015 9:12 am
Forum: Atomic Protector (formerly ASL)
Topic: Web application inventory scanner not working?
Replies: 4
Views: 6840

Re: Web application inventory scanner not working?

*bump* We haven't encountered a single ASL machine where the web application inventory scanner actually reported something. Is there anything we can do to further debug this component? Or can you take a look? This post from June 2014 never got a reply. I also noted that the APPINV rules are over a ...
by prupert
Thu Feb 26, 2015 9:06 am
Forum: Atomic Protector (formerly ASL)
Topic: Geoblock country but allow IP
Replies: 10
Views: 9091

Re: Geoblock country but allow IP

You could insert firewall rules in INPUT before ASL-GEO-BLACKLIST .
by prupert
Thu Feb 26, 2015 9:04 am
Forum: Atomic Protector (formerly ASL)
Topic: clear entire shun list
Replies: 11
Views: 10393

Re: clear entire shun list

Yes, just restart the HIDS.

Code: Select all

service ossec-hids restart