You are currently browsing the archives for the Releases category.

Our Sponsors

Die ISPConfig Entwicklung wird unterstützt von der projektfarm GmbH Lüneburg.

Archive for the ‘Releases’ Category

ISPConfig 3.1.11 Released – Sicherheitsupdate

Donnerstag, Januar 11, 2018 posted by admin

What’s new in ISPConfig 3.1.11

In the past weeks, we reviewed the ISPConfig sourcecode for further XSS issues and ISPConfig was tested with professional security test tools. Thank you very much to Fábián Patrik for his efforts in testing ISPConfig. This uncovered more places where ISPConfig was vulnerable to XSS attacks. For all attacks, a valid ISPConfig login was required to exploit the XSS vulnerability. This release fixes the XSS issues that were found. Besides that, it includes several other bugfixes and new features.

The ISPConfig IDS system was extended to have different attack score levels for users and the admin, this drastically reduced the false positive rate and allowed it to enable the IDS by default now. The IDS settings can be found in the file /usr/local/ispconfig/security/security_settings.ini

A new feature has been added to change the document root directory on nginx servers to a sub folder. More: https://git.ispconfig.org/ispconfig/ispconfig3/merge_requests/698

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.11.tar.gz

Changelog

https://git.ispconfig.org/dashboard/issues?milestone_title=3.1.11&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.10
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.11.tar.gz
tar xvfz ISPConfig-3.1.11.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.11 Released – Sicherheitsupdate

ISPConfig 3.1.10 Released – Sicherheitsupdate

Freitag, Dezember 29, 2017 posted by admin

What’s new in ISPConfig 3.1.10

This update fixes several XSS vulnerabilities that were found in ISPConfig. A valid ISPConfig login is required to exploit the XSS vulnerabilities. The release includes other bugfixes and some minor improvements as well. See changelog link below for details.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.10.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.10&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.10
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.10.tar.gz
tar xvfz ISPConfig-3.1.10.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.10 Released – Sicherheitsupdate

ISPConfig 3.1.9 Released – Wichtiges Sicherheitsupdate

Mittwoch, Dezember 6, 2017 posted by admin

What’s new in ISPConfig 3.1.9

This release contains an important security fix for an authenticated local root vulnerability in the ISPConfig website cron system, the vulnerability has the CVE number CVE-2017-17384 assigned and has been reported to us by Chris Kessler. The update should be installed immediately. All ISPConfig 3 versions before 3.1.9 are affected.

An attacker requires either the correct ISPConfig admin password or a remote user (valid username and password) which has the permissions to create cronjobs or a client login with permission to create cronjobs.

We received reports that the net is currently scanned for ISPConfig installations with weak admin passwords, especially for systems with password ‚admin‘. Ensure that your system uses a strong admin user password to protect your server!

The ISPConfig 3.1.9 release scans your system for potentially malicious cronjobs and will report them during update.

In case that you can not install the update right now, then a possible temporary attack prevention is to disable the cron plugin by removing the symlink like this:

rm -f /usr/local/ispconfig/server/plugins-enabled/cron_plugin.inc.php

It is not possible to create cronjobs from within ISPConfig after you deleted that symlink (cronjobs will show up in ISPConfig UI in that case but will not get added to the Linux cron.d directory). The symlink in plugins-enabled folder to the cron plugin in the plugins-available folder has to be added again to get the cron functionality back.

If you like to scan your system for potentially malicious cronjobs on the shell, use this command (copy / paste it on the shell as root user to execute it):

IFS=$'\n' ;
for F in $(find /etc/cron.d -type f -name "ispc_*") ; do
 USR=${F:17} ;
 if [[ "$USR" = "chrooted_"* ]] ; then
  USR=${USR:9} ;
 fi ;
 USR=${USR%.*} ;
 echo "Checking cron file $F for user $USR";
 for L in $(awk '{print $6}' "$F") ; do
  if [[ "$USR" != "$L" ]] ; then
   echo "WARNING: $F contains cron job for user $L" ;
  fi ;
 done ;
done

The 3.1.9 release contains some other minor bugfixes beside the security fix, please see release notes for details.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.9.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.9&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.10
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.9.tar.gz
tar xvfz ISPConfig-3.1.9.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.9 Released – Wichtiges Sicherheitsupdate

ISPConfig 3.1.7 Released

Montag, September 25, 2017 posted by admin

What’s new in ISPConfig 3.1.7

This release adds a new search path for the latest Let’s Encrypt certbot program and fixes some minor bugs.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.7.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.7&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.04
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.7.tar.gz
tar xvfz ISPConfig-3.1.7.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.7 Released

ISPConfig 3.1.6 Released

Donnerstag, Juli 20, 2017 posted by admin

What’s new in ISPConfig 3.1.6

This release adds remote API functions to set values in the global and system configuration and fixes some minor bugs.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.6.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.6&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.04
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.6.tar.gz
tar xvfz ISPConfig-3.1.6.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.6 Released

ISPConfig 3.1.5 Released

Donnerstag, Juni 29, 2017 posted by admin

What’s new in ISPConfig 3.1.5

This release contains an important security fix. A user that is logged into ISPConfig was able to view contact details of other users due to an insufficient privilege check. Some minor bugs have been fixed in this release as well, see changelog in issue tracker for details.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.5.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.5&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Stretch (9.0) and Debian testing
– Ubuntu 7.10 – 17.04
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.5.tar.gz
tar xvfz ISPConfig-3.1.5.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.5 Released

ISPConfig 3.1.2 Released

Mittwoch, Januar 25, 2017 posted by admin

What’s new in ISPConfig 3.1.2

This release contains a security fix and several bug fixes.

SSH user certificates were not created securely in ISPConfig versions < 3.1.2. The code to create the SSH private and public key has been completely rewritten and placed into a central function for easier maintenance in ISPConfig 3.1.2 to solve this problem. Thank you very much to Greg for reporting this issue.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.2.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.2&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Jessie (8.0) and Debian testing
– Ubuntu 7.10 – 16.10
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.2.tar.gz
tar xvfz ISPConfig-3.1.2.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.2 Released

ISPConfig 3.1.1 Veröffentlicht

Dienstag, Oktober 25, 2016 posted by admin

What’s new in ISPConfig 3.1.1

ISPConfig 3.1.1 adds support for Ubuntu 16.10 and fixes several bugs that were found in ISPConfig 3.1.

This version contains an updated apache vhost template file. In case that you created a custom vhost override file, then ensure to add the modifications of the SSL configuration into your custom template.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.1.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1.1&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Jessie (8.0) and Debian testing
– Ubuntu 7.10 – 16.10
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.1.tar.gz
tar xvfz ISPConfig-3.1.1.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1.1 Veröffentlicht

ISPConfig 3.1 released

Dienstag, September 27, 2016 posted by admin

What’s new in ISPConfig 3.1

ISPConfig 3.1 is the next generation of the ISPConfig hosting control panel with a completely renovated UI and a lot of new features. Here a few highlights:

  • New responsive User Interface based on the Bootstrap framework. The interface is responsive now which makes it easy to use ISPConfig on mobile devices.
  • Dkim support. Digital Signing of email’s with Dkim is now integrated.
  • DNSSEC support for creating signed DNS zones.
  • Let’s encrypt support. Create free SSL certificates with Let’s encrypt directly from within ISPConfig.
  • Management of XMPP Servers in ISPConfig.
  • Support for HHVM (Hip Hop Virtual Machine) as PHP engine.
  • Full PHP 7 support.
  • Support for Ubuntu 16.04.
  • New REST API (the SOAP API still exists).
  • Support for multiple default servers per client on multiserver installations.
  • Many small features, improvements, and bugfixes.  Please see changelog link below.

Screenshots

ispconfig_login       ispconfig_dashboard

FAQ

  • How can I update from ISPConfig 3.0.5? The ISPConfig 3.0.5 to 3.1 update is a normal ISPConfig update, just follow the update instructions below.
  • Will there be a new User Manual for ISPConfig 3.1?
    The new manual for ISPConfig 3.1 is available now. The manual describes on 434 pages the functions of ISPConfig 3.1, it shows how to use the software on all supported OS. Beside that, it includes new Multiserver and Cluster installation instructions for Debian 8
  • Will there be a new Billing Module for ISPConfig 3.1?
    The new Billing Module for ISPConfig 3.1 is ready and will be released tomorrow (Sept 28).

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Jessie (8.0) and Debian testing
– Ubuntu 7.10 – 16.04
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1.tar.gz
tar xvfz ISPConfig-3.1.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1 released

ISPConfig 3.1 Beta 2 released for testing

Freitag, Juni 24, 2016 posted by admin

What’s new in ISPConfig 3.1

ISPConfig 3.1 is the next generation of the ISPConfig hosting control panel with a completely renovated UI and a lot of new features. Here a few highlights:

  • New responsive User Interface based on the Bootstrap framework. The interface is responsive now which makes it easy to use ISPConfig on mobile devices.
  • Dkim support. Digital Signing of email’s with Dkim is now integrated.
  • DNSSEC support for creating signed DNS zones.
  • Let’s encrypt support. Create free SSL certificates with Let’s encrypt directly from within ISPConfig.
  • Management of XMPP Servers in ISPConfig.
  • Support for HHVM (Hip Hop Virtual Machine) as PHP engine.
  • Full PHP 7 support.
  • Support for Ubuntu 16.04.
  • New REST API (the SOAP API still exists).
  • Support for multiple default servers per client on multiserver installations.
  • Many small features, improvements and bugfixes.  Please see changelog link below.

Screenshots

ispconfig_login       ispconfig_dashboard

Please note that this is a beta version. Beta versions are released for testing purposes and not for installation on production systems.

FAQ

  • When will the ISPConfig 3.1 final version be released?
    The final version will be released in the next few weeks. The release date depends on the number of issues that were found in the current beta 2 version.
  • Will there be a new User Manual for ISPConfig 3.1?
    We are currently working on a new User manual für ISPConfig 3.1. The manual will be available for the Final release.
  • Will there be a new Billing Module for ISPCOnfig 3.1?
    A new Billing Module for ISPConfig 3.1 will be released when the ISPConfig 3.1 final is ready.

Download

The software can be downloaded here:

http://www.ispconfig.org/downloads/ISPConfig-3.1b2.tar.gz

Changelog

https://git.ispconfig.org/ispconfig/ispconfig3/issues?assignee_id=&author_id=&label_name=&milestone_title=3.1&scope=all&sort=id_desc&state=closed

Known Issues

Please take a look at the bug tracker:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

BUG Reporting

Please report bugs to the ISPConfig bug tracking system:

https://git.ispconfig.org/ispconfig/ispconfig3/issues

Supported Linux Distributions

– Debian Etch (4.0) – Jessie (8.0) and Debian testing
– Ubuntu 7.10 – 16.04
– OpenSuSE 11 – 13.2
– CentOS 5.2 – 7
– Fedora 9 – 15

Installation

The installation instructions for ISPConfig can be found here:

http://www.ispconfig.org/ispconfig-3/documentation/

Update

To update existing ISPConfig 3 installations, run these commands in the shell:

cd /tmp
wget http://www.ispconfig.org/downloads/ISPConfig-3.1b2.tar.gz
tar xvfz ISPConfig-3.1b2.tar.gz
cd ispconfig3_install/install
php -q update.php
Kommentare deaktiviert für ISPConfig 3.1 Beta 2 released for testing