In another post ( http://0entropy.blogspot.com/2012_03_01_archive.html ) we wrote about some perl scripts, bots, that were found in PLESK server installations. Apparently there is more on it. As described also in parallels forums, http://forum.parallels.com/showthread.php?t=258101 the attacks were quite elaborated. Attackers, using the bug http://kb.parallels.com/en/112303 were able to get access to PLESK installations and install backdoors in the systems. I’m using plural on backdoors, cause it’s not just one, there are quite a few.
In some systems /dev/shm/persist was created with the …
MAY



