<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Plesk 0Day For Sale As Thousands of Sites Hacked</title>
	<atom:link href="http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Mon, 20 May 2013 02:57:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Brian</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-95796</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Thu, 09 Aug 2012 06:33:41 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-95796</guid>
		<description><![CDATA[Any insight as to why kaspersky not detecting this...

my AVGfree system regales plesk threat and presence OK]]></description>
		<content:encoded><![CDATA[<p>Any insight as to why kaspersky not detecting this&#8230;</p>
<p>my AVGfree system regales plesk threat and presence OK</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dj</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-95368</link>
		<dc:creator>dj</dc:creator>
		<pubDate>Tue, 07 Aug 2012 13:47:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-95368</guid>
		<description><![CDATA[hi guys,

my friends server was also hit via plesk,
through the filemanager, and % in the urls with  the  client ids

untill now i only found and removed js code from my indexes, php and html

but now i found an other variant, in the index they insert an include statement, to include an other file situated and looking like a log file.

then it is decoded and executed.

it is quite advanced coding, getting ads from some server, and lots of code to detect if its a googlebot or so, and then keep quiet

i found it out nearly by chance
(no i am not going to tell how i found it, it might help the hacker)

so, try to search for files around the infection date.

this one is not detected by a virusscanner
(dowload the code and run a scanner over it doesnt work)

hope this helps someone, dj]]></description>
		<content:encoded><![CDATA[<p>hi guys,</p>
<p>my friends server was also hit via plesk,<br />
through the filemanager, and % in the urls with  the  client ids</p>
<p>untill now i only found and removed js code from my indexes, php and html</p>
<p>but now i found an other variant, in the index they insert an include statement, to include an other file situated and looking like a log file.</p>
<p>then it is decoded and executed.</p>
<p>it is quite advanced coding, getting ads from some server, and lots of code to detect if its a googlebot or so, and then keep quiet</p>
<p>i found it out nearly by chance<br />
(no i am not going to tell how i found it, it might help the hacker)</p>
<p>so, try to search for files around the infection date.</p>
<p>this one is not detected by a virusscanner<br />
(dowload the code and run a scanner over it doesnt work)</p>
<p>hope this helps someone, dj</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claire Towne</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-90938</link>
		<dc:creator>Claire Towne</dc:creator>
		<pubDate>Fri, 20 Jul 2012 11:19:10 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-90938</guid>
		<description><![CDATA[Is there any update on if and how it is possible to retrieve data?]]></description>
		<content:encoded><![CDATA[<p>Is there any update on if and how it is possible to retrieve data?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeffatrackaid</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-89904</link>
		<dc:creator>jeffatrackaid</dc:creator>
		<pubDate>Mon, 16 Jul 2012 19:13:43 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-89904</guid>
		<description><![CDATA[I am seeing more cases of web site files having javascript injections.  The entry point is via the Plesk File Manager.

I speculate that the attackers may have obtained the passwords months ago and if the password were not reset they are simply returning to get into the system.

The latest round of attacks we see are on July 6th and 9th.]]></description>
		<content:encoded><![CDATA[<p>I am seeing more cases of web site files having javascript injections.  The entry point is via the Plesk File Manager.</p>
<p>I speculate that the attackers may have obtained the passwords months ago and if the password were not reset they are simply returning to get into the system.</p>
<p>The latest round of attacks we see are on July 6th and 9th.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC.Tech</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-89569</link>
		<dc:creator>PC.Tech</dc:creator>
		<pubDate>Sun, 15 Jul 2012 18:00:32 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-89569</guid>
		<description><![CDATA[Plesk Panel 10.x for Windows...
*  http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-windows-updates-release-notes.html
15-Jul-2012 - &quot;... Fixed critical Plesk security issues found during internal security audit. All customers are highly recommended to update...&quot;

Plesk Panel 10.x for Linux...
- http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-linux-updates-release-notes.html
15-Jul-2012 - &quot;... Fixed critical Plesk security issues found during internal security audit. All customers are highly recommended to update...&quot;
.]]></description>
		<content:encoded><![CDATA[<p>Plesk Panel 10.x for Windows&#8230;<br />
*  <a href="http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-windows-updates-release-notes.html" rel="nofollow">http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-windows-updates-release-notes.html</a><br />
15-Jul-2012 &#8211; &#8220;&#8230; Fixed critical Plesk security issues found during internal security audit. All customers are highly recommended to update&#8230;&#8221;</p>
<p>Plesk Panel 10.x for Linux&#8230;<br />
- <a href="http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-linux-updates-release-notes.html" rel="nofollow">http://download1.parallels.com/Plesk/PP10/parallels-plesk-panel-10-linux-updates-release-notes.html</a><br />
15-Jul-2012 &#8211; &#8220;&#8230; Fixed critical Plesk security issues found during internal security audit. All customers are highly recommended to update&#8230;&#8221;<br />
.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC.Tech</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-89560</link>
		<dc:creator>PC.Tech</dc:creator>
		<pubDate>Sun, 15 Jul 2012 16:56:34 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-89560</guid>
		<description><![CDATA[- http://www.securitytracker.com/id/1027243
Jul 12 2012
CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1557 - 7.5 (HIGH)
Impact: Disclosure of system information, Disclosure of user information, User access via network
Version(s): prior to 10.4.x
Solution: The vendor has issued a fix.
The fix also includes a Mass Password Reset Script that must be executed to remove existing sessions and prevent a recurrence.
The vendor&#039;s advisory is available at:
- http://kb.parallels.com/en/113321

- https://secunia.com/advisories/48262
.]]></description>
		<content:encoded><![CDATA[<p>- <a href="http://www.securitytracker.com/id/1027243" rel="nofollow">http://www.securitytracker.com/id/1027243</a><br />
Jul 12 2012<br />
CVE Reference: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1557" rel="nofollow">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1557</a> &#8211; 7.5 (HIGH)<br />
Impact: Disclosure of system information, Disclosure of user information, User access via network<br />
Version(s): prior to 10.4.x<br />
Solution: The vendor has issued a fix.<br />
The fix also includes a Mass Password Reset Script that must be executed to remove existing sessions and prevent a recurrence.<br />
The vendor&#8217;s advisory is available at:<br />
- <a href="http://kb.parallels.com/en/113321" rel="nofollow">http://kb.parallels.com/en/113321</a></p>
<p>- <a href="https://secunia.com/advisories/48262" rel="nofollow">https://secunia.com/advisories/48262</a><br />
.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: YC</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-89348</link>
		<dc:creator>YC</dc:creator>
		<pubDate>Sat, 14 Jul 2012 18:27:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-89348</guid>
		<description><![CDATA[Hi Edosan,

Can you share with us some sample logs on how they grab the plesk passwords? I guess it will be much helpful for us in term of detection.]]></description>
		<content:encoded><![CDATA[<p>Hi Edosan,</p>
<p>Can you share with us some sample logs on how they grab the plesk passwords? I guess it will be much helpful for us in term of detection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: edosan</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-88861</link>
		<dc:creator>edosan</dc:creator>
		<pubDate>Fri, 13 Jul 2012 10:06:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-88861</guid>
		<description><![CDATA[This latest report got me a bit twitchy as we got hit really bad In February. What we noticed from our logs was that the original wave of attacks were doing nothing more than grabbing plesk passwords. So once patched you then needed to block 8443, patch plesk, change all passwords(domain users, clients and admin) and then ensure users didn&#039;t revert to old passwords. This was a LOT of effort and I&#039;m guessing many ISPs probably didn&#039;t really have a clue what was happening and didn&#039;t resolve the issue logically.  I suspect that this &#039;tool&#039; probably has the large pricetag because it has access to a large database of previouslt exploited servers as well as trying the original sql injection attack on agent.php...]]></description>
		<content:encoded><![CDATA[<p>This latest report got me a bit twitchy as we got hit really bad In February. What we noticed from our logs was that the original wave of attacks were doing nothing more than grabbing plesk passwords. So once patched you then needed to block 8443, patch plesk, change all passwords(domain users, clients and admin) and then ensure users didn&#8217;t revert to old passwords. This was a LOT of effort and I&#8217;m guessing many ISPs probably didn&#8217;t really have a clue what was happening and didn&#8217;t resolve the issue logically.  I suspect that this &#8216;tool&#8217; probably has the large pricetag because it has access to a large database of previouslt exploited servers as well as trying the original sql injection attack on agent.php&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anon</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-88854</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Fri, 13 Jul 2012 09:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-88854</guid>
		<description><![CDATA[yes, exactly -- easy to see it by ID/sequence]]></description>
		<content:encoded><![CDATA[<p>yes, exactly &#8212; easy to see it by ID/sequence</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: infodox</title>
		<link>http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/comment-page-1/#comment-88654</link>
		<dc:creator>infodox</dc:creator>
		<pubDate>Thu, 12 Jul 2012 18:43:08 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15887#comment-88654</guid>
		<description><![CDATA[Alan - Hackers generally do not fire exploits around willy-nilly, as that is a GREAT way to get nailed by a honeypot or to cock up and get yourself arrested. It is much preferred to spend a second checking your target before you let loose...]]></description>
		<content:encoded><![CDATA[<p>Alan &#8211; Hackers generally do not fire exploits around willy-nilly, as that is a GREAT way to get nailed by a honeypot or to cock up and get yourself arrested. It is much preferred to spend a second checking your target before you let loose&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 21/22 queries in 0.003 seconds using memcached
Object Caching 381/397 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-19 23:14:58 by W3 Total Cache -->