• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Plesk 8 Also Insecure, Even With Php Safe Mode On

M

Markus@

Guest
I just found an exploit when using Perl.

Via Perl you are able to access folders and files with incorrect file permission settings, same thing, cp /virus.script /directorywithwrongpermissions and then system("/dir/virus.script");

ET VOILA PLESK HACKED AGAIN!!!!!!!!!!!!!!!!!!!

Plesk also support hackers!
 
How does PHP safe mode being enabled have anything to do with a PERL exploit?
 
You do realize that PERL and PHP are two completely separate languages, handled by different interpreters, and processed completely separately from each other...right? I mean, come on! Stop blaming plesk for the insecurities you're having.

If I remember correctly, plesk uses mod_perl, why aren't you blaming the people over at the apache project, or the people at php, or the people at perl? I mean come on! You're just trying to blame everyone else for your inability to manage your server correctly. Granted, this will probably make you direct your attacks at me, but with your recent posts, I no longer care what you say.

Good luck with your control panel project, which you've stated you're starting. And best of luck securing it against people that really want in.
 
Simple, use a php script to upload or move CGI files to the /TMP directory and execute them via PHP.
 
Back
Top