Hacker publishes alleged zero-day remote code execution exploit for older Plesk versions

The exploit targets a vulnerability that only affects unsupported Plesk versions, the software's creator said

A hacker released what he claims is a zero-day exploit for older versions of the Parallels Plesk Panel, a popular Web hosting administration software package, that could allow attackers to inject arbitrary PHP code and execute rogue commands on Web servers.

The hacker uses the alias "Kingcope" and has published exploits for unpatched vulnerabilities before. He released the new Plesk exploit code Wednesday on the Full Disclosure mailing list.

The hacker claims the exploit was successfully tested against Plesk 9.5.4, Plesk 9.3, Plesk 9.2, Plesk 9.0 and Plesk 8.6 used in combination with the Apache Web server software on 32-bit and 64-bit Linux distributions including Red Hat, CentOS and Fedora. However, Parallels, the Seattle-based company that develops Plesk Panel, claims that Plesk 9.5 and later versions are not affected by the exploit.

"This vulnerability is a variation of the long known CVE-2012-1823 vulnerability related to the CGI mode of PHP only in older Plesk [versions]," a Parallels representative said Thursday via email. "All currently supported versions of Parallels Plesk Panel 9.5, 10.x and 11.x, as well Parallels Plesk Automation, are not vulnerable."

According to a page on the company's website, version 8 of the product has not been supported since September 2012 and Plesk version 9 will reach end of life Sunday.

Even if the latest versions of the software are not affected, widespread exploitation of this vulnerability is still likely to happen because servers running the old and affected versions of Plesk are unlikely to be regularly maintained, said Craig Williams, a threat researcher at Cisco, Wednesday in a blog post.

Williams analyzed the attack code released by Kingcope and said that "the script exploits the vulnerable versions of the Plesk control panel by injecting malicious PHP code, allowing successful attackers to execute arbitrary commands with the privileges of the Apache server userid."

A command executed by the exploit contains several arguments that are intended to disable security mechanisms that might exist on the server, he said. These include the "allow_url_include=on" argument which allows the attacker to include arbitrary PHP code and the "safe_mode=off" argument. "As a final step Suhosin, a PHP hardening patch, is put into simulation mode. This mode is designed for application testing, and effectively turns off the extra protection."

If a customer is using a legacy and no longer supported version of Parallels Plesk Panel, they should upgrade to the latest version, the Parallels representative said. The company already provided a workaround for the CVE-2012-1823 vulnerability for legacy versions of Plesk, the representative said.

"Those unable to disable the vulnerable version of Plesk or upgrade to more recent, unaffected code should consider additional hardening outside of PHP, such as running their Apache instance within a chroot environment or restricting access to the Plesk control panel, e.g. via IP ACLs [access control lists] or HTTP authentication," Williams said.

"Successful exploitation requires a ScriptAlias [configuration] for the php path using Apache's mod_alias," vulnerability management firm Secunia said Thursday in an advisory that rates the vulnerability as highly critical. That specific configuration is scriptAlias /phppath/ "/usr/bin/", according to Kingcope's exploit notes.

However, it's not clear how commonly this configuration is found in real world Plesk deployments. Two users who posted responses to Kingcope's email to the Full Disclosure mailing list said that they couldn't get the exploit to work because they couldn't find the phppath-related setting on Plesk installations they tried it on.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags secuniaParallelsExploits / vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?