Variation of previously reported vulnerability in older versions of Parallels Plesk Panel

 

A variation is being reported of a previously-reported zero-day vulnerability in older versions of Parallels Plesk Panel. Since the original vulnerability was first reported, the majority of Parallels Plesk Panel customers took the necessary steps to upgrade to a non-vulnerable version of the product.

 

Today only 4% of servers running Parallels Plesk Panel are potentially impacted. This means 96% of Parallels Plesk Panel servers have been updated to a non-vulnerable version of Parallels Plesk Panel.

 

If you are still running Parallels Plesk Panel 9.0 to 9.2, please take the action to upgrade today. There are multiple version options to upgrade to in order to help you secure and protect your customers.

 

How to upgrade

+ The best version to upgrade to is Parallels Plesk Panel 11.0. It has been available for over a year and is the version with the highest deployment rate, lowest support cost, best performance and, of course, highest security.

+ On June 13, 2013, Parallels will launch Parallels Plesk Panel 11.5. This new version will come with additional usability, performance and security benefits.

+ If you cannot upgrade to the latest version, you can update now to Parallels Plesk Panel 9.5.4. This is a direct upgrade through the AutoInstaller. On June 13 you can then upgrade to version 11.5.

 

If you are unable to upgrade at this time, you can apply a script to automatically update your Parallels Plesk Panel for Linux 9.0-9.2.3 server.  You can download that script (wrapper.zip) from the “Attachments” section of http://kb.parallels.com/116241.

 

Details about the vulnerability

 

This vulnerability is not new.  It is a variation of the long-known CVE-2012-1823 vulnerability related to the CGI mode of PHP in selected older and end-of-life versions of Parallels Plesk Panel. The exploit for this vulnerability uses a combination of two issues:

 

+ PHP vulnerability CVE-2012-1823 related to CGI mode used in older versions of Parallels Plesk Panel (http://kb.parallels.com/en/113818)

+ Parallels Plesk Panel phppath script alias usage in Parallels Plesk Panel versions 9.0-9.2

 

All currently supported versions of Parallels Plesk Panel 9.5.4, 10.x and 11.x, as well as Parallels Plesk Automation, are NOT vulnerable. Also, Parallels Plesk Panel 8.x (now end-of-life) is NOT vulnerable.

 

There also are some additional resources to insure that your Parallels Plesk Panel installation is secure, and malware, if present, is removed:

 

+ Parallels has created a comprehensive page on securing Parallels Plesk Panel at http://kb.parallels.com/en/114396

+ Parallels has created a malware removal tool at http://kb.parallels.com/en/115025

 

To stay on top of Parallels security communications please subscribe to our support e-mails by clicking here, subscribe to our RSS feed here and add our Knowledge Base browser plug-in here

 

Adam Bogobowicz, Sr. Director of Product Marketing


How to Recruit the Next Generation of Load and Performance Testers

Last month, I went to my engineering school, where I graduated 15 years ago, to attend the Annual Gala. While there, I met a few young engineers who asked about my job. This raised a question: “What would make them join my team?”
In the IT world, the demand for highly skilled software engineers continues to grow as application development becomes an integral part of more and more businesses around the globe. As more and more applications are highly connected and have strong SLAs and are addressing sensitive business issues, the demand for load and performance testers also grows.
Companies have been using creative techniques like using Big Data, Twitter and gamification to find top tech talent, but how do you get talented young engineers to 1) be interested in load testing and 2) want to work at your company in your team?

read more

Cloud Expo New York: Reduce Cloud Security Risks

The cloud security challenge is about more than new technologies, architectures and business models. It is about change. The organizational process of cloud adoption and migration executed by disparate IT teams and business units delivers point cloud and security solutions that create unnecessary gaps in an organization’s security posture. To reduce risk and maximize return on investment, organizations must take a long-term, integrated view of cloud security. They need a framework that is intelligent, comprehensive, easier to implement and identity-centric.
In his session at the 12th International Cloud Expo, McAfee identity expert Robert Craig from McAfee’s Identity Center of Expertise will discuss these emerging trends and challenges and how a Security Connected approach combined with advanced threat and web protection, single sign-on and authentication can do more than provide secure access to the cloud – it can, and will, improve your user’s experience with it.

read more

Panzura to Exhibit at Cloud Expo New York

SYS-CON Events announced today that Panzura, a leading provider of global cloud storage solutions, will exhibit at SYS-CON’s 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York.
Panzura optimizes enterprise data storage management and distribution in the cloud, making cloud storage simple and secure. Panzura’s revolutionary global cloud storage solution seamlessly combines the flexibility, performance and productivity benefits of distributed storage with the manageability, security and cost benefits of centralized storage, overcoming fundamental “administrator vs. user” and “budget vs. performance” conflicts. With Panzura, data location no longer affects usage.

read more

Cloud Expo New York: Agile IaaS with the OVH Dedicated Cloud

It is common to see providers deploy cloud instances using automation, but what happens when these same principles are applied to the provisioning of the infrastructure?
In his General Session at the 12th International Cloud Expo, Jean-Sebastien Bruneau, Cloud Architect at OVH.com, will provide insider information on how OVH, winner of the VMware Global Partner Network Award 2013, can make automation work to provide IaaS that scales within minutes.
Jean-Sebastien Bruneau is Cloud Architect at OVH.com. Based in Canada, he joined the team not long after OVH.com opened its first North American Datacenter and has been working his “Cloud-Fu” since. He divides his time evangelising, facilitating customers’ onboarding and leading the internal cloud training program.

read more

SAP to Buy E-Commerce Firm

SAP is buying hybris, a 16-year-old $85 million-a-year Swiss e-commerce company, expecting to deliver the next-generation e-commerce platform for on-premise and cloud deployment.
It claims the purchase, which many have expected for a long time, puts it at the leading edge of the consumer economy, raising the stakes in customer relationship management (CRM) and defining the next-generation customer experience.
Terms weren’t disclosed, but All Things Digital thinks the deal is costing SAP $1.2 billion-$1.5 billion.
hybris just got $30 million from the VCs in March including Meritech Capital Partners and Greylock Israel. Its majority investor is Huntsman Gay Global Capital (HGGC), a private investment firm based in Palo Alto, California.

read more

Skyera Shows Enterprise Solid-State Cloud Storage Systems at Cloud Expo NY

Dr. Radoslav Danilak, CEO and co-founder of Skyera Inc., will present on next-generation flash memory technologies to attendees of Cloud Expo New York, June 10-13 at the Javits Center in New York City. Skyera will also show its 44-terabyte skyHawk, a complete enterprise solid-state storage solution with the low latency and scalability that cloud services demand – with the highest density, smallest form-factor and lowest power consumption in the industry – in booth 214.
Danilak’s speech on using flash memory as primary storage for the cloud is featured on the afternoon of Wednesday, June 12 as part of the conference’s Cloud Storage, Security & Performance session.
According to Danilak, only a system-level approach to flash memory management can meet the increasing performance demands of the cloud while bringing the price of all solid-state systems to a level that is equal to high performance HDDs. Innovations are necessary to make the latest generation of 19/20 nm MLC flash memory usable in mainstream enterprise cloud storage. In addition, reducing high costs that keep flash memory from serving as primary storage (as compared to caches or tiers) is very important. His session will highlight flash technology trends for the cloud, and offer system level solutions that will advance flash memory in the enterprise cloud storage market.

read more

Centrify for SaaS Supports Office 365

Centrify, which made its bones making Microsoft’s popular Active Directory accessible to Redmond’s enemies list, is spreading its wings and snuggling up closer to Microsoft at the same time by throwing it something of a lifeline.
See, Microsoft expects Office 365 to be one of the fastest-growing businesses in its history. It’s already claimed it’s got a billion-dollar run rate. There’s only one little problem.
The widgetry Microsoft supplies for Active Directory integration – ADFS or Active Directory Federation Services – is a pain in the proverbial tail for both Microsoft’s field personnel and the channel, which is paid to sell Office 365 and hardly needs to spend hours wrestling with the slippery stuff since it actually takes pricey dedicated hardware and specialized knowledge of the operating system to get it up and running.

read more

Cloud Technology Partners to Demo PaaSLane at Cloud Expo New York

Cloud Technology Partners, a provider of transforming businesses with cloud solutions, has announced that it will provide the first public demonstrations of PaaSLane at next week’s 12 International Cloud Expo, June 10-13, at the Javits Center in New York City. Additionally, David Linthicum, senior vice president (SVP), will lead a session uncovering the true value of industry-specific clouds.
PaaSLane is a software tool that substantially reduces the time and effort required to migrate applications to the cloud. Traditionally, cloud migration assessments are a manual process that can take months and cost hundreds of thousands of dollars. PaaSLane automates the process by evaluating application source code against a customizable rules engine to identify cloud compliance and compatibility issues. To learn more and/or request to join the private beta release, please visit www.paaslane.com.

read more