• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

hacking with php shell

C

Christian Roehl

Guest
I have not found any thread or comment to that point. Do you made exeriences with php shell (http://phpshell.sourceforge.net/) already? Once php shell is installed on your plesk server you are able to execute shell commands, *delete files* or have control about all files/folder of other customers.

All you need is an existing account on your plesk server and users which disabled safe mode in order to install apps like joomla or wordpress.
 
i will provide access, but not official on that forum. Are you able to contact me directly?
 
Guys,

Could you please post results of your investigation with all necessary details how it can be reproduced?
 
i can not reproduce it on our servers ...

open_basedir prevent the access to other costumers ...
 
if you want I will prepare a test machine for you, potentially thats easier. Please keep me informed.
 
@danliker: lenny is running fine. So i should limit the issue to CentOS 5.4. PHP 5.1.6
 
Last edited by a moderator:
ok, i think i have found the bug ...

if you use fcgi the open_basdir and other php values are not set in http.include file ...
 
If you have found bug, please describe it with details and instruction how it can be reproduced. I will submit bugreport to developers in this case.
 
it is a php script, just download, unpack and upload it with ftp to an account with fcgi enabled and safe mode disabled ...
 
Use any user account on your plesk server (please use centos, debian is running fine). upload the files e.g. in your httpdocs folder. Configure the config.php with user, password. If there is any need I can prepare a server for limited time.
 
Ok. Thank you for information and cooperation.
I have submitted corresponding request to developers.
 
Back
Top