• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Problems with awstats???

I

Inno

Guest
I have following problems with awstats:

1. All icons and images of awstats seems to be missing.
2. domain.com/plesk-stat gives an index of the directory:

anon_ftpstat/ 02-Dec-2006 04:04 -
ftpstat/ 02-Dec-2006 04:04 -
logs/ 27-Jul-2006 04:07 -
webstat-ssl/ 02-Dec-2006 04:04 -
webstat/ 02-Dec-2006 04:03 -


Everybody can even access the raw log files:

access_log 02-Dec-2006 11:07 13K
access_log.processed 02-Dec-2006 04:03 6.4M
access_ssl_log 02-Dec-2006 11:09 32K
access_ssl_log.processed 02-Dec-2006 04:03 6.2M
error_log 02-Dec-2006 09:53 2.4M
error_ssl_log 02-Dec-2006 11:07 28M
xferlog_regular 02-Dec-2006 04:03 0
xferlog_regular.processed 02-Dec-2006 04:03 1.1M
 
Regarding the index files. It seems this has nothing to do with the upgrade. Is the same with webalizer and earlier versions of Plesk.

The only difference is that I had a forbidden message before the upgrade.

But spying on Plesk servers seems to be very easy. Just go to domain.com/plesk-stat/logs/access_log and hope that the directory isn't protected.
 
Nope, not yet. Maybe I have to. Not sure they would see it as a bug. I can't imagine that they don't know this issue.

I hope it has nothing to do with my configuration... does anybody else has this?
 
Yes, on domains that have unprotected stats everyone can access the domain's access_log, error_log and xferlog_regular (plus the rotated, processed versions of those files).

I think these files shouldn't even be accessible to people authorized to see password-protected stats.
 
Got an answer from Pesk support. They managed to reproduce the problem on Plesk 7.5 and 8.0 and have reported the problem to developers.

Clean install 8.1.0 does not have this problem. They are still checking it for upgrade 8.0 to 8.1
 
Back
Top