Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-10-2010, 02:56 PM   #1
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
:mad If your running Plesk 9 as control panel read your server may get hacked through pro(ftpd)

Ask your hosting company if they already patched the leak in psa-proftpd.
The exploit is out in the open and many server are already hacked.

Check http://forum.parallels.com/forumdisplay.php?f=552
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 04:37 PM   #2
comeplay
Confirmed User
 
comeplay's Avatar
 
Join Date: Nov 2004
Location: Greater Washington DC
Posts: 1,435
I woke up today to this issue.. 35+ load averages with 30+ proftpd connections from one IP.. culprit was this proftpd vuln make sure your current versions are 1.3.3c and not anything older!
__________________
Top virtual hosts for under 10$? www.hostmylife.com | icq 50663030
comeplay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 04:46 PM   #3
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Yes I guess already many servers got rooted.... ,
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 04:59 PM   #4
tonyparra
Confirmed User
 
tonyparra's Avatar
 
Industry Role:
Join Date: Jul 2008
Location: In your back seat with duck tape
Posts: 4,568
any host care to reassure your customers this wont be a issue?
__________________

High Performance Vps $10 Linode
Manage your Digital Ocean, Linode, or Favorite Cloud Server. Simple, fast, and secure Server Pilot
tonyparra is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:02 PM   #5
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
I have been using pure-ftpd for many years now ...
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:03 PM   #6
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
stop frikken using control panels to control a server for chrissakes!

they aren't that difficult to to control on the command line...
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:07 PM   #7
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Quote:
Originally Posted by tonyparra View Post
any host care to reassure your customers this wont be a issue?
It is a big issue already many servers are (automagically) root hacked.
new botnet born?
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:15 PM   #8
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Quote:
Originally Posted by borked View Post
stop frikken using control panels to control a server for chrissakes!

they aren't that difficult to to control on the command line...
For a hosting company command line is not an option. You want clients to configure settings themselves. Ar you really from Wageningen ??? Does Unitas (the student club) still exists?
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:18 PM   #9
comeplay
Confirmed User
 
comeplay's Avatar
 
Join Date: Nov 2004
Location: Greater Washington DC
Posts: 1,435
Quote:
Originally Posted by borked View Post
stop frikken using control panels to control a server for chrissakes!

they aren't that difficult to to control on the command line...
I think the issue is more the proftpd version then the control panel
__________________
Top virtual hosts for under 10$? www.hostmylife.com | icq 50663030
comeplay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:31 PM   #10
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Quote:
Originally Posted by comeplay View Post
I think the issue is more the proftpd version then the control panel


I only know (from experience...)| that plesk 9 is affected maybe other panels (directadmin / cpanel are vulnerable too.


more info.

1.3.3c - Released 29-Oct-2010
--------------------------------
- Bug 3521 - Telnet IAC processing stack overflow.


http://www.proftpd.org/docs/NEWS-1.3.3c
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:47 PM   #11
comeplay
Confirmed User
 
comeplay's Avatar
 
Join Date: Nov 2004
Location: Greater Washington DC
Posts: 1,435
Quote:
Originally Posted by sinnerscorner View Post
I only know (from experience...)| that plesk 9 is affected maybe other panels (directadmin / cpanel are vulnerable too.
The VPS i had an issue with uses directadmin.. the IP that was connected with 30ish instances was running plesk tho
__________________
Top virtual hosts for under 10$? www.hostmylife.com | icq 50663030
comeplay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 05:51 PM   #12
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
Quote:
Originally Posted by comeplay View Post
I think the issue is more the proftpd version then the control panel
The control panel often complicates the issue and makes security updates more difficult.

http://forum.parallels.com/showpost....4&postcount=26

The advice to ditch control panels (where at all possible) is very sound. Either that or hire someone to administer the box.
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 06:04 PM   #13
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
I can't stand using plesk and direct admin
for me there's only one control panel and thats cPanel / WHM
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 08:04 PM   #14
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
anyone running directadmin needs to update their servers also this hack will bring down your server with connections.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-10-2010, 10:14 PM   #15
izzynew
Confirmed User
 
Industry Role:
Join Date: May 2009
Posts: 174
Damn!
Thanks for the heads up.
izzynew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 12:31 AM   #16
boneless
Confirmed User
 
boneless's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: in your head
Posts: 3,625
Quote:
Originally Posted by sinnerscorner View Post
For a hosting company command line is not an option. You want clients to configure settings themselves. Ar you really from Wageningen ??? Does Unitas (the student club) still exists?
mijn vriedin komt uit wageningen, volgens haar bestaat die club nog. Zal het eens aan haar pa vragen die woont er nog steeds.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
boneless is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 03:56 AM   #17
tom3k
Confirmed User
 
Industry Role:
Join Date: Nov 2007
Posts: 105
proftpd is for amateurs.

be a man, run vsftpd.
tom3k is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 04:28 AM   #18
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
i have my proftp turned off and just use sftp instead
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 12:20 PM   #19
Shoplifter
Richest man in Babylon
 
Shoplifter's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,678
Quote:
Originally Posted by comeplay View Post
I woke up today to this issue.. 35+ load averages with 30+ proftpd connections from one IP.. culprit was this proftpd vuln make sure your current versions are 1.3.3c and not anything older!
Yes I have seen the same thing. This is not really about Plesk at all and I would immediately have your host fix this. It's only a matter of time before the script kiddies have something to really screw you up through this.
Shoplifter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 12:46 PM   #20
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Quote:
Originally Posted by Shoplifter View Post
Yes I have seen the same thing. This is not really about Plesk at all and I would immediately have your host fix this. It's only a matter of time before the script kiddies have something to really screw you up through this.

It is already there:

Un autre exploit pour la faille telnet IAC dans ProFTPD

Kingcope a mis en ligne, le 7 novembre 2010, un script Perl qui permet d'exploiter cette faille sur un nombre plus important de plateformes :

* FreeBSD 8.1 i386, ProFTPD 1.3.3a Server (binary)
* FreeBSD 8.0/7.3/7.2 i386, ProFTPD 1.3.2a/e/c Server (binary)
* Debian GNU/Linux 5.0, ProFTPD 1.3.2e Server (Plesk binary)
* Debian GNU/Linux 5.0, ProFTPD 1.3.3 Server (Plesk binary)
* Debian GNU/Linux 4.0, ProFTPD 1.3.2e Server (Plesk binary)
* Debian Linux Squeeze/sid, ProFTPD 1.3.3a Server (distro binary)
* SUSE Linux 9.3, ProFTPD 1.3.2e Server (Plesk binary)
* SUSE Linux 10.0/10.3, ProFTPD 1.3.2e Server (Plesk binary)
* SUSE Linux 10.2, ProFTPD 1.3.2e Server (Plesk binary)
* SUSE Linux 11.0, ProFTPD 1.3.2e Server (Plesk binary)
* SUSE Linux 11.1, ProFTPD 1.3.2e Server (Plesk binary)
* SUSE Linux SLES 10, ProFTPD 1.3.2e Server (Plesk binary)
* CentOS 5, ProFTPD 1.3.2e Server (Plesk binary
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-11-2010, 12:47 PM   #21
sinnerscorner
Confirmed User
 
Industry Role:
Join Date: Jul 2004
Posts: 194
Quote:
Originally Posted by boneless View Post
mijn vriedin komt uit wageningen, volgens haar bestaat die club nog. Zal het eens aan haar pa vragen die woont er nog steeds.


Ok ja vraag maar. Ik ben benieuwd of ze dan nog steeds halverwege de Wageningse berg
zitten... H
__________________
-- ok there is no sig here --
sinnerscorner is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.