• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Please beaware of a breaking change in the REST API on the next Plesk release (18.0.62).
    Starting from Plesk Obsidian 18.0.62, requests to REST API containing the Content-Type header with a media-type directive other than “application/json” will result in the HTTP “415 Unsupported Media Type” client error response code. Read more here

Web_user Security Problem

would creating a vhost/vhost_ssl conf file possibly solve the issue?
 
that is the change I made. I rebooted the server and then I passed the test. I have not retested again because it puts a major load on the server.

I'm not sure about the vhost_ssl. sorry.
 
Is there some way for me to test if UserDir is disabled (without running a full pCI scan)?
 
im not sure if this is a real test... and Im really tired right now but if you go to somedomain.com/~someuser

if webusers are disabled it gives a 404 not found error instead of a 403 forbidden. (this assumes that directory listing is disabled and there is no index.htm in the webusers root) I guess you could just setup a webuser in plesk under a domain and then put an index page in the root and then see if it displays.

Sorry not much help. im a windows guy lost in a sea of plesk/linux
 
Originally posted by JointTech
Sorry not much help. im a windows guy lost in a sea of plesk/linux [/B]

Thanks for the tip -- I didn't think of checking that way -- like you I'm a long-time windows guy...
 
Back
Top