It’s very common these days for hosting providers to offer cloud-based hosting solutions to their customers. In configuring these servers ourselves, and in interactions with our customers’ servers, an issue has come to our attention where the dhclient script does not preserve locally-configured hostnames. This means that hostnames configured on the command line might not remain through a reboot. We wante to provide a workaround solution for this while continuing to investigate a more permanent, long-term solution. What …
Archive for security
Save the date! The next WordCamp US will be held on November 1-3, 2019, in beautiful St Louis, Missouri. One of our largest events of the year, WordCamp US is a great chance to connect with WordPress enthusiasts from around the world. This is also the event that features Matt Mullenweg’s annual State of the […]
WordPress 5.0.1 is now available. This is a security release for all versions since WordPress 3.7. We strongly encourage you to update your sites immediately. Plugin authors are encouraged to read the 5.0.1 developer notes for information on backwards-compatibility. WordPress versions 5.0 and earlier are affected by the following bugs, which are fixed in version […]
What can go wrong without the best web hosting platform? [Infographic]
The post What can go wrong without the best web hosting platform? [Infographic] appeared first on Plesk.
Say Hello to the New Editor We’ve made some big upgrades to the editor. Our new block-based editor is the first step toward an exciting new future with a streamlined editing experience across your site. You’ll have more flexibility with how content is displayed, whether you are building your first site, revamping your blog, or […]
The third release candidate for WordPress 5.0 is now available! WordPress 5.0 will be released on December 6, 2018. This is a big release and needs your help—if you haven’t tried 5.0 yet, now is the time! To test WordPress 5.0, you can use the WordPress Beta Tester plugin or you can download the release candidate here (zip). For details about […]
WordPress 5.0 is almost ready for release, including an all-new content editing experience. Volunteers all across the project are gearing up for the launch and making sure everything is ready. Read on to find out what’s been happening and how you can get involved. WordPress 5.0 Close to Launch The release date for WordPress 5.0 […]
The second release candidate for WordPress 5.0 is now available! This is an important milestone, as we near the release of WordPress 5.0. The WordPress 5.0 release date has shifted from the 27th to give more time for the RC to be fully tested. A final release date will be announced soon, based on feedback from […]
The first release candidate for WordPress 5.0 is now available! This is an important milestone, as we near the release of WordPress 5.0. The WordPress 5.0 release date has shifted from the 27th to give more time for the RC to be fully tested. A final release date will be announced soon, based on feedback on […]
Plesk partner Sucuri saves Val from hacking ordeal #WCSEA
Valentin Vesa’s charity website was constantly attacked by hackers, despite all his efforts. Until Sucuri stepped in. Carole Olinger tells his story, as told by Val himself at WCSEA.
The post Plesk partner Sucuri saves Val from hacking ordeal #WCSEA appeared first on Plesk.
WordPress 5.0 Beta 5 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test this WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
cPanel’s support teams thrive on customer feedback. We work hard to ensure that we are meeting our customer’s expectations and providing them with the best experience. That begins with us trying to understand our customer’s reactions to the support that we provide. The best means of doing that is via our feedback system. We’ve decided to make a few changes to how customers leave feedback for our Technical Support and Customer Service teams. cPanel …
WordPress 5.0 Beta 4 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
WordPress 5.0 Beta 3 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
To keep everyone aware of big projects and efforts across WordPress contributor teams, I’ve reached out to each team’s listed representatives. I asked each of them to share their Top Priority (and when they hope for it to be completed), as well as their biggest Wins and Worries. Have questions? I’ve included a link to […]
Teams across the WordPress project are working hard to make sure everything is ready for the upcoming release of WordPress 5.0. Find out what’s going on and how you can get involved. The Plan for WordPress 5.0 Early this month, the planned release schedule was announced for WordPress 5.0, which was updated a few weeks […]
WordPress 5.0 Beta 2 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
WordPress 5.0 Beta 1 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version, and if you are using an existing test site be sure to update the Gutenberg plugin to v4.1. There are […]
If you’ve ever logged in to WHM as a root-level user, you’ve assuredly seen a box with a notification of a new or improved feature. This dialogue box is known as the “Feature Showcase,” and has allowed us at cPanel to present information about changes to cPanel & WHM. Since its creation, the Feature Showcase was only available for use by cPanel. However, we’ve made some changes to the functionality of the Feature Showcase …
How to Build a cPanel Hosting Environment on Amazon AWS
Let’s say you need to find hosting for multiple web applications with cPanel backend access so clients cannot access each other’s backends. What can you do to create a secure hosting environment without paying for several different hosting accounts? Why not host it yourself?! Disclaimer: If you have one or two lightweight websites, this probably isn’t the most cost effective route to go, however, if you are currently paying to host several websites and have …
[20181005] – Core – CSRF hardening in com_installer
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 2.5.0 through 3.8.12
- Exploit type: CSRF
- Reported Date: 2018-September-26
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17858
Description
Added additional CSRF hardening in com_installer actions in the backend.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181004] – Core – ACL Violation in com_users for the admin verification
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 1.5.0 through 3.8.12
- Exploit type: ACL Violation
- Reported Date: 2017-December-27
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17855
Description
In case that an attacker gets access to the mail account of an user who can approve admin verifications in the registration process he can activate himself.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181003] – Core – Access level Violation in com_tags
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.1.0 through 3.8.12
- Exploit type: ACL Violation
- Reported Date: 2018-June-20
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17857
Description
Inadequate checks on the tags search fields can lead to an access level violation.
Affected Installs
Joomla! CMS versions 3.1.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181002] – Core – Inadequate default access level for com_joomlaupdate
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 2.5.4 through 3.8.12
- Exploit type: Object Injection
- Reported Date: 2018-June-21
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17856
Description
Joomla’s com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled access of Administrator-level users to access com_joomlaupdate and trigger a code execution.
Affected Installs
Joomla! CMS versions 2.5.4 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181001] – Core – Hardening com_contact contact form
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 2.5.0 through 3.8.12
- Exploit type: Incorrect Access Control
- Reported Date: 2018-September-17
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17859
Description
Inadequate checks in com_contact could allowed mail submission in disabled forms.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
The end of the cPanel Conference always triggers a mixture of feelings for me. The completion of the project means a lot of pride, and there’s a huge amount of relief, but it’s also bitter-sweet to know it’ll be a whole year before we get together again. To everyone that attended, sponsored, or exhibited at the 2018 cPanel Conference, thank you! We do this for you, and you continue to make it worth it. A …
Today is the first day of the 2018 cPanel Conference. We’re in the middle of setting everything up right now, getting ready to open up conference check-in and registration, and anticipating tonight’s networking party at Chapman and Kirby. We’ve spent the last 12 months planning this year’s conference, and we are ready to rock! Return of the Lab! This year the cPanel Lab is returning. In case you are unfamiliar, the cPanel Lab is a collection of …
The Month in WordPress: September 2018
The new WordPress editor continues to be a major focus for all WordPress contribution teams. Read on to find out some more about their work, as well as everything else that has been happening around the community this past month. Further Enhancements to the New WordPress Editor Active development continues on Gutenberg, the new editing […]
There are a lot of things we are looking forward to at this year’s conference. Engaging talks, fantastic networking sessions, super cool swag, and of course, some of the best evening events in the industry. We are bringing it back to our hometown of Houston, TX and we cannot wait to give you the grand tour! We have so much in store for our attendees that we’ve put together this checklist. By the time you all …
Earlier this year one of our technical analysts, Peter Elsner, wrote a tutorial on how to get the most from cPanel’s technical support. It hits on everything you should provide to our support team, but it is a great resource for any support request you submit to any team. A support team wants to solve your problem as much as you want to get it resolved, and clear information up front helps to …