New vulnerability?

Security annoucements of interest to the AtomiCorp community, such as vulnerabilities in third party applications.
DarkF@der
Forum Regular
Forum Regular
Posts: 313
Joined: Thu May 07, 2009 12:46 pm

New vulnerability?

Unread post by DarkF@der »

Hello,

has anyone noticed this?

http://forum.parallels.com/showthread.p ... e-in-Plesk


It looks like there's a vulnerability is out.
It has nothing to do with the new roundcube vulnerability some also do not use plesk.


Greets
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: New vulnerability?

Unread post by mikeshinn »

Hard to say at this point, nothing thats being discussed by the bad guys at least. As for the various spam tools discussed in that thread, ASL already stops scripts from running in /tmp, unless someone is not running the ASL kernel.

As for the spam tools themselves, there are already rules that detect and block all of them, even the Mizo script someone mentioned. We already detect it and block it.

When we know more, we'll definitely be able to comment on what this is or is not. For now, if you're using the ASL kernel any malware that gets installed as Apache wont run.
Post Reply