Page 1 of 1
critical security plesk issue
Posted: Mon Mar 05, 2012 11:44 am
by nobody
Guys take a look at this. I just saw it and pushed right away an update to plesk 10.4.4. I hope I don't have problems with the update. It affects all plesk editions except 10.4.4 according to parallels. The best part is that there is no hotfix for plesk 10.3.1 !
http://kb.parallels.com/en/113321
Re: critical security plesk issue
Posted: Mon Mar 05, 2012 1:11 pm
by nobody
Scott and Mike,
Havent you found a any way to filter again using modsecurity plesk panel ?
I miss those times when I could sleep slightly better at night... !
Re: critical security plesk issue
Posted: Mon Mar 05, 2012 3:32 pm
by BruceLee
Re: critical security plesk issue
Posted: Mon Mar 05, 2012 7:26 pm
by scott
Yup! This framework will let us add the WAF to any web based service... and maybe ftp but I didnt spend a lot of time on that.
Re: critical security plesk issue
Posted: Mon Mar 05, 2012 8:39 pm
by Blake@Parallels
nobody wrote:Guys take a look at this. I just saw it and pushed right away an update to plesk 10.4.4. I hope I don't have problems with the update. It affects all plesk editions except 10.4.4 according to parallels. The best part is that there is no hotfix for plesk 10.3.1 !
http://kb.parallels.com/en/113321
Note, this was address for 10.3.1 in MicroUpdate #5 in September 2011 (updates were also issued at that time for 9.5 and 8.6). Further, no base version (e.g. without MU's applied) were vulnerable after 10.4.0 in November 2011.
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 7:02 am
by nobody
scott wrote:Yup! This framework will let us add the WAF to any web based service... and maybe ftp but I didnt spend a lot of time on that.
Damn. How did I miss on that ? Fine job once again !
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 9:33 am
by faris
For the avoidance of doubt, I assume this is the same issue with Agent that we've discussed
http://www.atomicorp.com/forum/viewtopi ... =13&t=5731 or is it something different?
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 9:56 am
by faris
Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 11:08 am
by Blake@Parallels
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 11:08 am
by Blake@Parallels
faris wrote:Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.
For 8.6, this issue was resolved via MU#2 - released in September 2011.
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 12:55 pm
by nobody
Guys Plesk 10.4.4 works like a charm up till now. Which is a pleasant surprise. Never happened before
Blake when will they fix the issue in which you can move customers between ressellers ? This was a major stepback from version 9 to version 10 ...
Re: critical security plesk issue
Posted: Tue Mar 06, 2012 1:04 pm
by faris
Blake@Parallels wrote:faris wrote:Incidentally, there does appear to be a new MU for Plesk 8.6. MU11. Nothing to do with Agent. Looks related to Webmail to me.
For 8.6, this issue was resolved via MU#2 - released in September 2011.
Thank you for update.
Re: critical security plesk issue
Posted: Thu Mar 08, 2012 4:11 pm
by moondog604
My 8.6 is patched. I'm Mr Linux/Plesk Newb Question Man today.
1. I also running a 9.3, so I guess I have to update to 9.5.4?
2. In theory should I have any problems upgrading if I updated the PHP to 5.2 using the AtomicCorp repo?
3. Is it safer to install the updates one at a time or can I jump straight to 9.5.4?
Thanks in adavance!
Re: critical security plesk issue
Posted: Thu Mar 08, 2012 4:37 pm
by BruceLee
1. I would upgrade
2. You never know, each installation/servermight have different settings. Take care of a godd and complete backup
3. I stick with updating plesk over yum. Than i run the autoinstaller to install MU's. If I would go (which I don't do) and do it via webinterface of Plesk I would update one-by-one.
But thats just my opinion.
Re: critical security plesk issue
Posted: Thu Mar 08, 2012 10:17 pm
by nobody
Guys. Its the first time that I see great improvement in Plesk after 3 years. Plesk 10.4.4 seems to actually function ! I still seek to find what it has broken, thats good !
