How to fix HTTPoxy vulnerability in cPanel, Plesk or other Linux / Windows servers
HTTPoxy is a vulnerability with CGI environments, that allows an attacker to re-direct web traffic through an arbitrary proxy server.
HTTPoxy is a vulnerability with CGI environments, that allows an attacker to re-direct web traffic through an arbitrary proxy server.
A CVE-2014-3566 vulnerability in SSLv3 protocol named Poodle was identified by the Google security team. There is an additional whitepaper available from OpenSSL that also… Read More »How to secure Plesk servers from SSL V3 Poodle Vulnerability?
On Oct 14th Google published details of an SSL 3.0 vulnerability, which allows an attacker to secure session through a man-in-the-middle attack. Support for SSL 3.0 is available in all popular mail, ftp and web clients, which makes all your clients vulnerable to an exploit based on this bug. Since SSL 3.0 is an 18 year old obsolete technology, we recommend it to be disabled in all cPanel servers.
Here is a quick script for you to check if your cPanel/WHM server is vulnerable. Execute the following as root. If you get ANY cipher output, your server can be considered vulnerable.Read More »How to secure cPanel server from SSLV3 Poodle Vulnerability?