• The new Python extension is now available. It allows customers to deploy and manage WSGI-based Python applications on their websites directly from Plesk.
  • Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Spamassassin 2.6x per-user configuration

P

ProfiTiger

Guest
Help needed: Spamassassin 2.6x per-user configuration

Does anybody know, if the file user_prefs (configuration-file for Spamassassin, located in /var/qmail/mailnames/domainname/mailboxname) is generated via script on mailbox-creation or is copied from somewhere? The default user_prefs has only 4 lines (without razor, pyzor, dcc, autolearn...). It would be very usefull for me to know this, so I could save much time, because now I have to copy the file I configured in each new mailbox via ssh. I have some scripts which act on domain-creation (for awstats p.e.), but I did not find a handler or a variable from which I can get the mailboxname like it is stored in qmail/mailnames for copying user_prefs-file via script on mailbox creation.
 
watch out with awstats 6 has a hole that allows people to execute remote commands, had someone use it to wget a backdoor and execute it on 6.1 but the firewall stopped them getting to it luckily.

Warning, a security hole exists in old AWStats versions (from 5.0 to 6.3) when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody" or "wwwroot").
If you use AWStats with a recent version or if AWStats is not available as a CGI, you are safe. If not, it is highly recommanded to upgrade to 6.4 version, or higher, that fix all known security holes.
 
Back
Top