Resultaten 31 tot 45 van de 108
Pagina 3 van de 8 Eerste 1 2 3 4 5 ... LaatsteLaatste
Geen
  1. #31
    Remote exploit Plesk API
    moderator
    7.022 Berichten
    Ingeschreven
    29/07/03

    Locatie
    Nijmegen

    Post Thanks / Like
    Mentioned
    12 Post(s)
    Tagged
    0 Thread(s)
    175 Berichten zijn liked


    Naam: Mike
    Bedrijf: admin.nu
    URL: www.admin.nu
    Registrar SIDN: Ja
    KvK nummer: 09139651

    Stonden die udp floods niet pas voor 31 maart op de agenda, of is dit test draaien

  2. #32
    Remote exploit Plesk API
    +32 3 7478056
    1.087 Berichten
    Ingeschreven
    24/05/05

    Locatie
    [BE] Aalst

    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Naam: Joeri B.
    Bedrijf: GlobalServe BVBA
    Functie: CEO / CTO
    URL: globalserve.be
    Ondernemingsnummer: 0875203878
    View be.linkedin.com/in/joeribeirens's profile on LinkedIn

    Hackers maken wachtwoorden buit bij Proserve via Plesk-lek

    http://tweakers.net/nieuws/80462/hac...plesk-lek.html

  3. #33
    Remote exploit Plesk API
    geregistreerd gebruiker
    7 Berichten
    Ingeschreven
    13/04/11

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Naam: ex-user

    New bad news!

    Hi all,

    last night I found a server, which was definetly patched, being attacked and the attackers went away with the passwords - on a Plesk 9.5.4 patchlevel 17.

    I checked and compared the files the patch replaces, and yes, I had only the patched files on the server.

    This means: There might be cases, when even the Parallels patch does not secure anything.

    The only thing that really helped is breaking the API, by running a

    cat /dev/null > /usr/local/psa/admin/plib/api-rpc/Agent.php

    This way the attackers receive a HTTP 500 and can't fetch anything. If you don't use the API for centralized Plesk management, this should be the recommended action.

  4. #34
    Remote exploit Plesk API
    moderator
    7.022 Berichten
    Ingeschreven
    29/07/03

    Locatie
    Nijmegen

    Post Thanks / Like
    Mentioned
    12 Post(s)
    Tagged
    0 Thread(s)
    175 Berichten zijn liked


    Naam: Mike
    Bedrijf: admin.nu
    URL: www.admin.nu
    Registrar SIDN: Ja
    KvK nummer: 09139651

    Problem is without any further information from plesk, and details about that machine, the machine itself could also be compromised. Doesnt mean that the patch from plesk is incorrect.

  5. #35
    Remote exploit Plesk API
    geregistreerd gebruiker
    7 Berichten
    Ingeschreven
    13/04/11

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Naam: ex-user

    @Mikey

    we're running some quite sophisticated surveillance stuff for our own servers, so I can say for this server (which is only under our own control), that it

    - does not contain other hacks
    - is not rooted
    - had no other logins the last 6 month then the regular FTP/Mail/Plesk logins
    - is and was on the latest kernel and OS packages level
    - Plesk was not modified compared to other or fresh installations.

    Otherwise I wouldn't have shot in this warning.

  6. #36
    Remote exploit Plesk API
    [--]
    854 Berichten
    Ingeschreven
    28/05/06

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)
    67 Berichten zijn liked


    Naam: R
    Registrar SIDN: ja
    KvK nummer: 20125757

    we also manage a fully uptodate plesk 9.5.4 which is also compromised the same way. No FTP logins for the past few months, no plesk logins. logs show they mis-used the rpc-xml
    Parallels asked if they could take a look at the server, credentials were sent a week ago, but they didn't login yet..
    Guess they really have no clue what to do or they don't take it seriously enough...

  7. #37
    Remote exploit Plesk API
    45North Websolutions
    449 Berichten
    Ingeschreven
    02/05/07

    Locatie
    Gouda / Amsterdam

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: 24400745 / 30213423
    Ondernemingsnummer: nvt

    Just checked, but on the only one system that is compromised here (microupdates weren't applied automaticly) i still see some polls on agent.php but no data was forged. But to be sure, i nulled the Agent.php.

  8. #38
    Remote exploit Plesk API
    geregistreerd gebruiker
    7 Berichten
    Ingeschreven
    13/04/11

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Naam: ex-user

    Until now I saw it also only on one out of several hundred patched Plesk 9.5.4 - but nulling the Agent.php - seems to be the best solution, although I have no idea wherelse this API is used for. There might be a connection to the Plesk Migration Manager...

  9. #39
    Remote exploit Plesk API
    geregistreerd gebruiker
    120 Berichten
    Ingeschreven
    25/01/07

    Locatie
    nvt

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    1 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    I see alot of requests were send to agent.php 2 months ago!
    And suddenly they start using the passwords.

    So if the patch was only installed like a month ago, then its possible they got your password before patching it.
    Make sure you change all the passwords.

  10. #40
    Remote exploit Plesk API
    moderator
    5.444 Berichten
    Ingeschreven
    12/09/05

    Locatie
    Zuid Holland

    Post Thanks / Like
    Mentioned
    10 Post(s)
    Tagged
    0 Thread(s)
    110 Berichten zijn liked


    Naam: Stijn
    KvK nummer: 14074337

    Facebook is inmiddels down, toeval?

  11. #41
    Remote exploit Plesk API
    Geregistreerd Gebruiker
    4.755 Berichten
    Ingeschreven
    23/04/05

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    15 Post(s)
    Tagged
    0 Thread(s)
    353 Berichten zijn liked


    Naam: Toin Bloo
    Bedrijf: Dommel Hosting
    URL: www.dommelhosting.nl
    ISPConnect: Lid
    KvK nummer: 17177247

    en weer up... denk niet dat facebook op Plesk draait

    (oh je was de smiley vergeten )

  12. #42
    Remote exploit Plesk API
    moderator
    5.444 Berichten
    Ingeschreven
    12/09/05

    Locatie
    Zuid Holland

    Post Thanks / Like
    Mentioned
    10 Post(s)
    Tagged
    0 Thread(s)
    110 Berichten zijn liked


    Naam: Stijn
    KvK nummer: 14074337

    Citaat Oorspronkelijk geplaatst door t.bloo Bekijk Berichten
    en weer up... denk niet dat facebook op Plesk draait

    (oh je was de smiley vergeten )
    Waarom zou Facebook op Plesk moeten draaien om de site te kunnen ddosen op poort 53/dns?

  13. #43
    Remote exploit Plesk API
    geregistreerd gebruiker
    854 Berichten
    Ingeschreven
    13/01/11

    Locatie
    Breda

    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    76 Berichten zijn liked



    Citaat Oorspronkelijk geplaatst door Stewie Bekijk Berichten
    Facebook is inmiddels down, toeval?
    Denk het niet want dit zal zonder meer met de Plesk "hack" te maken hebben en er zullen nog genoeg scripts in de CGI staan die nu wederom aktief zijn geworden......

  14. #44
    Remote exploit Plesk API
    geregistreerd gebruiker
    120 Berichten
    Ingeschreven
    25/01/07

    Locatie
    nvt

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    1 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Is inderdaad door de Plesk hack dat facebook down was.
    De command & control pagina verwees naar de dns servers van facebook.

    Nu is de command & control weer leeg. maar ze kunnen het op elk moment weer aanzetten.

  15. #45
    Remote exploit Plesk API
    Geregistreerd Gebruiker
    4.755 Berichten
    Ingeschreven
    23/04/05

    Locatie
    Eindhoven

    Post Thanks / Like
    Mentioned
    15 Post(s)
    Tagged
    0 Thread(s)
    353 Berichten zijn liked


    Naam: Toin Bloo
    Bedrijf: Dommel Hosting
    URL: www.dommelhosting.nl
    ISPConnect: Lid
    KvK nummer: 17177247

    Citaat Oorspronkelijk geplaatst door Stewie Bekijk Berichten
    Waarom zou Facebook op Plesk moeten draaien om de site te kunnen ddosen op poort 53/dns?
    omdat ik niet verder denk dan mijn neus lang is

    [naief]waarom zou iemand facebook down willen hebben[/naief]

Pagina 3 van de 8 Eerste 1 2 3 4 5 ... LaatsteLaatste

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics