Archive for January, 2012
[+] Plesk 10.4 for Windows Migration Agent has been updated. Improved error reporting and several bug fixes were included to this release. You can download new version of Migration agent here. We strongly recommend you to update your local copy if any.
The following bugs have been fixed:
[-] Automatic key update fails for KAV if the additional key is installed as a part of PowerPack
The following bugs have been fixed:
[-] Automatic key update fails for KAV if the additional key is installed as a part of PowerPack
Social network Bebo is still inaccessible after an apparent technical error took the site offline yesterday.
We hereby declare 2012 as the Year of the WordPress Meetup. You’ll want to get in on this action. So what is a WordPress Meetup? Basically, it’s people in a community getting together — meeting up — who share an interest in WordPress, whether they be bloggers, business users, developers, consultants, or any other category of person able to say, “I use WordPress in some way and I like it, and I want to meet other people who can say the same.
Plesk Panel 10.4.4 MU#14 for Linux and Windows
The following bugs have been fixed:
[-] Atmail upgrade failed on action ‘Inserting old Atmail database data…’
[-] Automatic key update fails if KAV additional key is installed, but KAV itself is not.
[-] Can not connect service nodes using CLI gate
[-] Cannot change FTP user’s password if “Setup of potentially insecure web scripting options” disabled on subscription
Parallels Plesk Panel Troubleshooting Posters
We would like to introduce you Plesk Troubleshooter Posters.
In knowledge base article you can find them for Linux and Windows versions of Plesk.
Please feel free to discuss these posters in special thread on Parallels Forum http://forum.parallels.com/showthread.php?t=246206
The following bugs have been fixed:
[-] Atmail upgrade failed on action ‘Inserting old Atmail database data…’
[-] Automatic key update fails if KAV additional key is installed, but KAV itself is not.
[-] Can not connect service nodes using CLI gate
[-] Cannot change FTP user’s password if “Setup of potentially insecure web scripting options” disabled on subscription
Attacks resume against US Department of Justice
The United States Department of Justice appears to be under attack for the second time since the popular MegaUpload file sharing site was taken down.
In order to know that you need to add an ID to a rule you will have already found the error in the logs. To white list the rule this requires the rule to have an ID. All of the […] ↓ Read the rest of this entry…
Backups are very important to a website. If something should happen to the server, whether it be a hardware failure or breech of security, it is always good to have a copy or 2 to revert to. Backups can be […] ↓ Read the rest of this entry…
Whitelist A Rule in Mod Security # Find Modsec Errors cat /usr/local/apache/logs/error_logs | grep -i modsec # Check the domain logs if you don’t see it in the apache logs cat /usr/local/apache/domlogs/$DOMAIN | grep -i modsec # Add this […] ↓ Read the rest of this entry…
# Download and unzip wordpress cd /home/$USER/public_html wget http://wordpress.org/latest.zip unzip latest.zip rm latest.zip # remove superfluous directory mv wordpress/* ./ rmdir wordpress/ # Make wordpress writeable by the webserver/or USER mkdir wp-content/uploads wp-content/cache chown apache:apache wp-content/uploads wp-content/cache chown -R $USER. […] ↓ Read the rest of this entry…
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 1.7.3 and all earlier versions
- Exploit type: XSS Vulnerability
- Reported Date: 2012-January-22
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 1.7.3 and all earlier 1.7 and 1.6 versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by David Jardin
Contact
The JSST at the Joomla! Security Center.
[20120103] – Core – Information Disclosure
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: Information Disclosure
- Reported Date: 2011-December-19
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to information disclosure.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Jean-Marie Simonet
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: XSS Vulnerability
- Reported Date: 2011-November-16
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Ankita Kapadia
Contact
The JSST at the Joomla! Security Center.
[20120101] – Core – Information Disclosure
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: Information Disclosure
- Reported Date: 2012-January-07
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to information disclosure.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Erwan Peton – Intrinsec
Contact
The JSST at the Joomla! Security Center.
Plesk Panel 10.4.4 MU#13 for Linux and Windows
New feature has been added:
[+] (Windows only) Support of PHP 5.3 has been added. More details in article http://kb.parallels.com/en/113179
The following bugs have been fixed:
[-] Cross-site scripting in health monitor
[-] Web presence Builder has session identifier without HttpOnly flag
[-] Synchronization of subscription with Service Plan doesn’t work if Service Plan has disabled webhosting
[-] (Linux only) Licence key update failures aren’t logged
[-] (Linux only) Receiving DrWeb license key doesn’t work
[-] (Windows only) Cannot create MSSQL database if MySQL databases limit is 0
[-] (Windows only) Health Monitor fails to create configuraion files on Turkish Windows
cPanel Releases Fixes for cPanel & WHM 11.30
The newest cPanel & WHM release, 11.30.5.6, improves Google Chrome support. This update for cPanel & WHM resolves an issue with handling form submissions by newer versions of Google Chrome. The error affected file uploads in the cPanel File Manager…
New feature has been added:
[+] (Windows only) Support of PHP 5.3 has been added. More details in article http://kb.parallels.com/en/113179
The following bugs have been fixed:
[-] Cross-site scripting in health monitor
[-] Web presence Builder has session identifier without HttpOnly flag
[-] Synchronization of subscription with Service Plan doesn’t work if Service Plan has disabled webhosting
[-] (Linux only) Licence key update failures aren’t logged
[-] (Linux only) Receiving DrWeb license key doesn’t work
[-] (Windows only) Cannot create MSSQL database if MySQL databases limit is 0
[-] (Windows only) Health Monitor fails to create configuraion files on Turkish Windows
WordPress.org is officially joining the protest against Senate Bill 968: the Protect IP Act that is coming before the U.S. Senate next week. As I wrote in my post a week ago, if this bill is passed it will jeopardize internet freedom and shift the power of the independent web into the hands of corporations. […]
Oracle Critical Patch Update (CPU) Advisory – January 2012
AWstats was updated to version 7.0 for Parallels Plesk Panel 10.4.4
AWstats was updated to version 7.0 for Parallels Plesk Panel 10.4.4 on RPM-based OSes:
– CentOS 5
– CentOS 6
– RedHat 5
– RedHat 6
– SuSE 11.3
– SuSE 11.4
– CloudLinux 5
– CloudLinux 6
Parallels Plesk 10.4.4 AWstats 7.0 support
AWstats was updated to version 7.0 for Parallels Plesk Panel 10.4.4 on RPM-based OSes:
– CentOS 5
– CentOS 6
– RedHat 5
– RedHat 6
– SuSE 11.3
– SuSE 11.4
– CloudLinux 5
– CloudLinux 6
“Operation Italy” takes down government website
Plans by Anonymous to launch a distributed denial of service attack against www.governo.it were changed half an hour before the attack was scheduled to commence.
Plesk Panel 10.4.4 MU#12 for Linux and Windows
[+] Added possibility to hide advertisement in Plesk Panel. More details in article How to hide promos in Parallels Plesk Panel?
The following bugs have been fixed:
[-] (Windows only) Backups fails on dumping tomcat for sites
[-] (Linux only) Cannot change php safe_mode status via panel if FastCGI mode is used
[-] Domain alias zone is synced with main domain, even if DNS zone sync is disabled
[-] Domain disk space statistics is not displayed if amount exceeds 2Gb on 32-bit systems
[-] (Windows only) Hosting settings cannot be changed if FrontPage is enabled on a domain
[-] Migration from FreeBSD fails because of ‘df’ illegal option
[-] Backup files rotation o FTP repository fails in some cases.
[-] Listing of files in backup FTP repository fails in some cases.
[-] (Windows only) There is able to override system user home path at creating new additional FTP account
[+] Added possibility to hide advertisement in Plesk Panel. More details in article How to hide promos in Parallels Plesk Panel?
The following bugs have been fixed:
[-] (Windows only) Backups fails on dumping tomcat for sites
[-] (Linux only) Cannot change php safe_mode status via panel if FastCGI mode is used
[-] Domain alias zone is synced with main domain, even if DNS zone sync is disabled
[-] Domain disk space statistics is not displayed if amount exceeds 2Gb on 32-bit systems
[-] (Windows only) Hosting settings cannot be changed if FrontPage is enabled on a domain
[-] Migration from FreeBSD fails because of ‘df’ illegal option
[-] Backup files rotation o FTP repository fails in some cases.
[-] Listing of files in backup FTP repository fails in some cases.
[-] (Windows only) There is able to override system user home path at creating new additional FTP account
Parallels Plesk Panel 10.4.4 is Stable since the Micro-Update #11!
The Plesk Service team is proud to announce that Parallels Plesk Panel 10.4.4 has been switched to the Stable mode.
To get Plesk 10.4.4 in Stable you have to install the Micro-Update #11 (or later) which delivers more than 60 fixes in total.
We are going to continue improving Plesk 10.4.4 until next major release is available.
Please continue helping us to identify bugs and drawbacks to make Plesk better.
You are an agent of change. Has anyone ever told you that? Well, I just did, and I meant it. Normally we stay away from from politics here at the official WordPress project — having users from all over the globe that span the political spectrum is evidence that we are doing our job and […]
Threats to the web hosting industry (Anti-SOPA and Anti-PIPA)
Dear Hosting Providers, We believe the Stop Online Piracy Act (SOPA) and the Protect IP Act (PIPA) bills recently introduced by the U.S. Congress pose severe threats to the hosting industry as a whole and we ask that you take…