• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

What is this "security concept" all about?

schlimpf

Basic Pleskian
Hello,

I am just wondering what kind of security Plesk Panel is trying to reach with things like open_basedir etc.
As an attacker, if I can execute PHP on the server, I can just execute a perl script which then can read all dirs/files that are readable by apache from the COMPLETE server. There is as far as I know no way to prevent this with only Plesk configuration.
So basically I try to break in some CMS like WordPress, upload a PHP script with it and then I got a whole lot more possibilities as "just" messing with the httpdocs folder.
This will of course work if Perl is DISABLED for the domain.

Feedback from the Plesk team is greatly appreciated.

If anyone is concerned about his/her security and dont know how to fix issues like this, you can contact me via PM.

Best
Mario
 
Last edited:
How about a chrooted environment for the apache process and/or the PHP FastCGI processes? I think this would be a huge step forward in security and willl give plesk a killer feature that is not available on competitor software like cPanel!
 
Back
Top