Search

Language:  
Search for:

Available article translations:

Parallels Plesk Panel security best practices

APPLIES TO:
  • Parallels Plesk 11.x for Linux
  • Parallels Plesk 10.x for Linux
  • Parallels Plesk 9.x for Linux/Unix
  • Parallels Plesk 11.x for Windows
  • Parallels Plesk 10.x for Windows
  • Parallels Plesk 9.x for Windows

Question

Are there any tips for keeping Parallels Plesk Panel (PP) secure?

Answer

Yes. Here is a list of things you may want to do:

Note: Some of these features are available only as of version 11.

1. First, make sure you go through the list provided in the following Knowledge Base article:

114396 Securing Parallels Plesk Panel: Best Practices to Prevent Threats

The article above lists the most common causes of server intrusions, along with ways to prevent and eliminate them.

2. Do not forget to check the Securing Panel section of the Administrator's guide. Topics covered in this section include the following:
  • Restricting administrative access (from specific IP addresses)
  • Setting up the minimum password strength
  • Turning on the Enhanced Security mode
  • SSL protection
3. Linux users may also check the advanced documentation pages related to PP for Linux security: Enhancing Security. This documentation covers the following topics:
  • Restricting script execution in the /tmp directory
  • Configuring site isolation settings
  • Protecting users from running tasks on behalf of root
4. If you are dealing with credit cards, this document is worth reading:

Meeting PCI DSS Requirements for Parallels Plesk Panel Suite 11

5. It is recommended to be aware of these issues:

9689 FTP users have access to root directory on server
11239 SLAAC Attack - 0day Windows Network Interception Configuration Vulnerability
112171 Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
113321 Remote vulnerability in Plesk Panel (CVE-2012-1557)
114625 PP accepts both old and new admin passwords when integrated to CBM
115942 Public issues VU#310500, CVE-2013-0132, CVE-2013-0133

6. These articles may also be useful in certain scenarios:

1323 How can I run Rootkit Hunter with the update option?
1357 [Security] Defending against a SYN-Flood (DOS) Attack
1763 [Info] How can I ensure that Apache does not allow the SSL 2.0 protocol, which has known weaknesses?
7027 [How to] RKHunter warning improvement
8119 How to prevent your Parallels Plesk Panel from brute-force attacks
112156 How to set up a file audit on Windows server

TIP: Feel free to subscribe to updates to this article in order to keep track of new security issues.



f4c89357a6ff7298f273cb70f9d95452 56797cefb1efc9130f7c48a7d1db0f0c c81e59b61af9dca603ba03b14aabe968 42844a8183c58f5bd71c7d59929707e6 1d151d16e47c6f92bbf62d50eb32c4a2 9f8baf78266b4e54525d1c6bf06305a5 12c6f6bd6775cb701defb57d79fe96f6 db229c4740d60cf9f63ce5e5f42872fc e26cd5a43fdb23cb2c65dd477ab20f95 824237ce663843af86f93897fbd8e2f8

FEEDBACK
Was this article helpful?
Tell us how we may improve it.
Yes No
 
 
 
 
 
 
Desktop Virtualization
- Parallels Desktop 9 for Mac
- Parallels Transporter
- Parallels Desktop Switch to Mac Edition
- Parallels Desktop for Mac Enterprise Edition
- Parallels Management-Mac for Microsoft SCCM
Server Virtualization
- Parallels Cloud Server
- Parallels Containers for Windows 6.0 Beta
- Parallels Virtuozzo Containers
Automation
- Parallels Automation
- Parallels Automation for Cloud Infrastructure
- Parallels Business Automation Standard
- Parallels Virtual Automation
- Parallels Plesk Panel Suite
- Web Presence Builder
- Parallels Plesk Automation
- Parallels Small Business Panel
- Value-added Services for Hosters
- Parallels Partner Storefront
Services & Resources
- Cloud Acceleration Services
- Professional Services
- Support Services
- Training & Certification