• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question How to secure Plesk against CGI/Perl Hacks?

stevewest15

New Pleskian
Hello,

I thought we had our plesk servers pretty secure but it seems Plesk apache allows cgi scripts to read and access files across all customers. Any recommendations on how others handle securing their plesk servers from cgi/perl uploaded hacking tools?

We had a customer site hacked thru Joomla (php) and then hackers uploaded a cgi script specific to Plesk to scan all sites (ie /var/www/sites/*/httpdocs/) for sensitive files (like wp-config.php, configuration.php, etc). The hackers cgi script was able to make symlinks of other users sensitive files locally and I assume it was able to read those files as cgi/perl run as apache user. :-(

I'm checking w/ Plesk to see why on the Service Plan, the setting is enabled for "Restrict the ability to follow symbolic links" but at the subscription level, it's disabled for all customers. :-( I tested it on multiple Plesk servers and it seems enabling this setting at the service plan and running sync doesn't actually update at the plan level.

Would appreciate any helpful recommendation on what others are doing to better secure Plesk again CGI/Perl hacks which run as apache user instead of system user of subscription.

Thanks,

SW
 
Back
Top