• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Security Alert!

A

agbate

Guest
I just noticed this problem today when I was running into an issue with horde not finding the database properly.

It appears that the log file, /var/log/psa-horde.log is owned by apache and not root.

Personally, I find this quite scary considering that log lines such as this are present:

DB Error: extension not found: mysql, , /var/lib/mysql/mysql.sock, unix, localhost, horde, horde, XXXXXXXX, utf8, horde, horde.perms, horde_datatree, horde_datatree_attributes

Where XXXXXXXX is the database password, which if it wasn't changed for user 'horde' is also the password of the admin login for mysql.

Considering the number of phpbb/nuke/mambo exploits that allow users to gain access to user apache, this issue concerns me.

I just thought I'd share this with everyone incase no one noticed. Just another reason to make sure all your scripts are up to date.

Cheers.

Adam.
 
Back
Top