• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Perl threat

K

knocx

Guest
it is possible to traverse and read whole server files with perl/cgi scripts even using plesk suexec.

i.e one can read /etc/proftpd.conf ..etc you guess the rest!


is there a pre-caution for that? how can perl be hardened on run time (like php safe_mode directive).

or is the only way to disable perl handler in apache
 
Back
Top