Stonden die udp floods niet pas voor 31 maart op de agenda, of is dit test draaien :)
Afdrukvoorbeeld
Stonden die udp floods niet pas voor 31 maart op de agenda, of is dit test draaien :)
Hackers maken wachtwoorden buit bij Proserve via Plesk-lek
http://tweakers.net/nieuws/80462/hac...plesk-lek.html
Hi all,
last night I found a server, which was definetly patched, being attacked and the attackers went away with the passwords - on a Plesk 9.5.4 patchlevel 17.
I checked and compared the files the patch replaces, and yes, I had only the patched files on the server.
This means: There might be cases, when even the Parallels patch does not secure anything.
The only thing that really helped is breaking the API, by running a
cat /dev/null > /usr/local/psa/admin/plib/api-rpc/Agent.php
This way the attackers receive a HTTP 500 and can't fetch anything. If you don't use the API for centralized Plesk management, this should be the recommended action.
Problem is without any further information from plesk, and details about that machine, the machine itself could also be compromised. Doesnt mean that the patch from plesk is incorrect.
@Mikey
we're running some quite sophisticated surveillance stuff for our own servers, so I can say for this server (which is only under our own control), that it
- does not contain other hacks
- is not rooted
- had no other logins the last 6 month then the regular FTP/Mail/Plesk logins
- is and was on the latest kernel and OS packages level
- Plesk was not modified compared to other or fresh installations.
Otherwise I wouldn't have shot in this warning.
we also manage a fully uptodate plesk 9.5.4 which is also compromised the same way. No FTP logins for the past few months, no plesk logins. logs show they mis-used the rpc-xml
Parallels asked if they could take a look at the server, credentials were sent a week ago, but they didn't login yet..
Guess they really have no clue what to do or they don't take it seriously enough...
Just checked, but on the only one system that is compromised here (microupdates weren't applied automaticly) i still see some polls on agent.php but no data was forged. But to be sure, i nulled the Agent.php.
Until now I saw it also only on one out of several hundred patched Plesk 9.5.4 - but nulling the Agent.php - seems to be the best solution, although I have no idea wherelse this API is used for. There might be a connection to the Plesk Migration Manager...
I see alot of requests were send to agent.php 2 months ago!
And suddenly they start using the passwords.
So if the patch was only installed like a month ago, then its possible they got your password before patching it.
Make sure you change all the passwords.
Facebook is inmiddels down, toeval?
en weer up... denk niet dat facebook op Plesk draait
(oh je was de smiley vergeten :))
Is inderdaad door de Plesk hack dat facebook down was.
De command & control pagina verwees naar de dns servers van facebook.
Nu is de command & control weer leeg. maar ze kunnen het op elk moment weer aanzetten.