• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Inviting everyone to the UX test of a new security feature in the WP Toolkit
    For WordPress site owners, threats posed by hackers are ever-present. Because of this, we are developing a new security feature for the WP Toolkit. If the topic of WordPress website security is relevant to you, we would be grateful if you could share your experience and help us test the usability of this feature. We invite you to join us for a 1-hour online session via Google Meet. Select a convenient meeting time with our friendly UX staff here.

Question How to secure Plesk against CGI/Perl Hacks?

stevewest15

New Pleskian
Hello,

I thought we had our plesk servers pretty secure but it seems Plesk apache allows cgi scripts to read and access files across all customers. Any recommendations on how others handle securing their plesk servers from cgi/perl uploaded hacking tools?

We had a customer site hacked thru Joomla (php) and then hackers uploaded a cgi script specific to Plesk to scan all sites (ie /var/www/sites/*/httpdocs/) for sensitive files (like wp-config.php, configuration.php, etc). The hackers cgi script was able to make symlinks of other users sensitive files locally and I assume it was able to read those files as cgi/perl run as apache user. :-(

I'm checking w/ Plesk to see why on the Service Plan, the setting is enabled for "Restrict the ability to follow symbolic links" but at the subscription level, it's disabled for all customers. :-( I tested it on multiple Plesk servers and it seems enabling this setting at the service plan and running sync doesn't actually update at the plan level.

Would appreciate any helpful recommendation on what others are doing to better secure Plesk again CGI/Perl hacks which run as apache user instead of system user of subscription.

Thanks,

SW
 
Back
Top