Security vulnerabilities in Pligg CMS version 1.0.4
Submitted by Bogdan Calin on September 3, 2010 – 8:09 pm
While beta testing the latest version of Acunetix WVS v7, we found a large number of security vulnerabilities in various web applications. In the following days we will publish some of these vulnerabilities. Note that we will not publish vulnerabilities found in applications that are not commonly used or in beta stage.
One of the tested web applications is Pligg;
Pligg is an open source CMS (Content Management System) that you can download and use for free. Pligg CMS provides social publishing software that encourages visitors to register on your website so that they can submit content and connect with other users.
The following web vulnerabilities were found in Pligg CMS Version 1.0.4;
- SQL injection in “/pliggcms_1_0_4/login.php“, parameter “email“.
- Cross-site Scripting vulnerability in “/pliggcms_1_0_4/user.php“, parameter “category“.
Technical details about each web vulnerability are below;
1. SQL injection in “/pliggcms_1_0_4/login.php“, parameter “email“.
Source file: /var/www/pliggcms_1_0_4/libs/db.php line: 222
Additional details:
SQL query:
1 |
SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer' |
“mysql_query” was called.
Stack trace:
1 |
1. ezSQL_mysql::query([string] "SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer'") |
2 |
2. ezSQLcore::get_row([string] "SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer'") |
Sample HTTP Request:
01 |
POST /pliggcms_1_0_4/login.php HTTP/1.1 |
02 |
Acunetix-Aspect-Password: 082119f75623eb7abd7bf357698ff66c |
03 |
Acunetix-Aspect: enabled |
04 |
Content-Length: 68 |
05 |
Content-Type: application/x-www-form-urlencoded |
06 |
Cookie: PHPSESSID=4c7d8e111f3ec5e90e664e26f365cc04; mnm_user=tmp; mnm_key=dG1wOjIyZkpqa1BveUhCVFE6NWY1YTg5NTJkYzUzODI4NGYwOTA0Y2Q0NTUzNzk5NDE%3D; template=wistie |
07 |
Host: webapps7:80 |
08 |
Connection: Keep-alive |
09 |
Accept-Encoding: gzip,deflate |
10 |
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) |
11 |
|
12 |
email=sql'injection&processlogin=3&return=%2fpliggcms_1_0_4%2f |
2. Cross-site Scripting vulnerability in “/pliggcms_1_0_4/user.php”, parameter “category”.
Attack details
URL encoded GET input categorywas set to ” onmouseover=prompt(938687) bad=”
The input is reflected inside a tag element between double quotes.
The input is reflected inside a tag element between single quotes.
Sample HTTP Request:
01 |
POST /pliggcms_1_0_4/user.php?category=%22%20onmouseover%3dprompt%28938687%29%20bad%3d%22&id=&keyword=Search..&login=&module=&page=&search=&view=search HTTP/1.1 |
02 |
Content-Length: 9 |
03 |
Content-Type: application/x-www-form-urlencoded |
04 |
Cookie: PHPSESSID=4c7d8e111f3ec5e90e664e26f365cc04; mnm_user=tmp; mnm_key=dG1wOjIyZkpqa1BveUhCVFE6NWY1YTg5NTJkYzUzODI4NGYwOTA0Y2Q0NTUzNzk5NDE%3D; template=wistie |
05 |
Host: webapps7:80 |
06 |
Connection: Keep-alive |
07 |
Accept-Encoding: gzip,deflate |
08 |
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) |
09 |
|
10 |
username= |
These vulnerabilities were reported to the Pligg team on 22/7/2010 via the contact form from their website and they were fixed in latest version of Pligg. If you are using Pligg, download the latest version from their website.
Acunetix 7 makes web application security checking easier and more cost effective
New scanning engine with improved vulnerability detection AND verification makes finding and fixing security issues in web applications easier.
September 1, 2010 – Acunetix, a market leader in web application security scanning technology, today announced version 7 of its popular Web Vulnerability Scanner. With the new human like vulnerability verifying techniques, revolutionary scanning engine and support for a wider variety of web applications, Acunetix re-establishes its technology lead in web application security. Acunetix WVS Version 7 also features improved performance, less false positives and detection of a wide range of new web vulnerability types.
“With Acunetix WVS v7 we focused on finding more vulnerabilities, reducing false positives, and on improving scanner performance,” said Robert Abela, Acunetix Technical Manager. “As a result, Acunetix 7 is now 300% faster, can reduce false positives up to 50% and detects new vulnerabilities such as stored directory traversal. This helps businesses reduce the time and resources needed to secure their web applications significantly.”
Unique vulnerability verifying technique reduces false positives
Acunetix v7 includes new advanced vulnerability verifying techniques which result in much less false positives, and thus saves time of security administrators trying to reproduce such situations. Such accuracy is achieved by sending a number of test inputs to the web application, and depending on the response, Acunetix v7 will automatically determine which web vulnerability checks to launch against the web application.
New faster scanning engine reduces time to scan a website by up to 300%
Acunetix Web Vulnerability Scanner Version 7 includes a new fast multi-threaded scanner that can scan on more threads at a time and more efficiently. Scans that could take hours to complete now can be done in minutes, depending on website structure and web applications.
Acunetix 7 reduces time needed to fix security vulnerabilities
When a web security threat is discovered, Acunetix WVS Version 7 presents the developers with a more precise and understandable technical and vulnerability remediation information, to help them fix the issue in a much shorter time. To improve understanding, different variants of the vulnerability are gathered in one detailed vulnerability report. Acunetix v7 can also re-check a fix for a particular vulnerability, without having to rescan the entire website.
Detect more web vulnerabilities
Thanks to the new revolutionary scanning engine and website crawler, Version 7 is able to find much more vulnerabilities than ever before. The new site crawler’s in-depth analysis of the website presentation layer discovers more website parameters and inputs. Acunetix 7 is therefore capable of finding many more vulnerabilities in a larger variety of different web applications.
Scan a wider range of web applications
Acunetix v7 is also able to crawl and scan a wider variety of web technologies. Support for Web 2.0 applications has been improved, and also session handling. All of the advanced penetration testing tools have been rewritten to support Web 2.0 requests, such as JSON, XML and more.
HTTP authentication
Acunetix WVS v7 now supports more than a single pair of HTTP credentials for the same host. Thanks to the new HTTP authentication settings node, one can pre-define credentials per host, directory and even file.
Easily create your own vulnerability checks
Acunetix v7 now has improved support for creating custom vulnerability checks. Vulnerability checks are written in JavaScript, the most popular scripting language with web developers, and can thus be easily adjusted or extended. A scripting tool and SDK are also available to assist developers in writing custom web vulnerability and security checks.
Lower cost subscription licenses
Subscription based licenses now also include the maintenance agreement and are thus significantly cheaper. In addition free support and free version upgrades are included.
Other Features
■New graphical scan status interface shows more information about a web scan in progress
■Avoid the lengthy process of manually analyzing the code by specifying the label or tag instead of actual parameter name
■Verify that AcuSensor Technology is correctly installed with a simple click of a button
■During a scan, less bandwidth is consumed and less stress is put on the server thanks to improved network traffic handling
■A number of new network security checks have been added and other ones improved.
Acunetix WVS Trial Edition
Download Acunetix Web Vulnerability Scanner v7 trial edition from here
HUGE SAVINGS ON HP PROLIANT PROCESSORS and OPTIONS
HUGE SAVINGS ON HP PROLIANT PROCESSORS and other OPTIONS
(HP FACTORY SEALED/REFURBISHED/FULL HP WARRANTY)
| Part Number | Description | Price | Available Qty. |
| 456908-B21 | AMD Opteron 8347HE 1.9GHz Quad Core 2MB BL685c Processor RMKT Option Kit | $750 | 8 |
| 516050-B21 | AMD Opteron 8382 2.6GHz Quad Core BL685c G5 RMKT Processor Option Kit | $940 | 2 |
| 494267-B21 | AMD Opteron 8384 2.7GHz Quad Core BL685c G5 2P RMKT Processor Option Kit | $1,835 | 2 |
| 488099-B21 | HP BLc3000 DDR2 RMKT Onboard Administrator | $450 | 6 |
| 464895-B21 | Intel Xeon E5205 1.86GHz Dual Core 6MB BL260c G5 RMKT Processor Option Kit | $195 | 1 |
| 448373-B21 | Intel Xeon L5240 3.0GHz Dual Core 6MB DL160 G5 Processor RMKT Option Kit | $485 | 10 |
| 448371-B21 | Intel Xeon X5272 3.40GHz Dual Core 6MB DL160 G5 RMKT Processor Option Kit | $999 | 47 |
| 495614-B21 | Intel Xeon X5482 3.20GHz Quad Core 1MB DL160 G5 RMKT Processor Option Kit | $1,069 | 29 |
| 445513-B21 | HP ProLiant 100 G5 Lights-Out 100c Remote Management RMKT Card | $75 | 1 |
| 459357-B21 | HP 120GB 1.5G 5.4K rpm SFF (2.5-inch) Non-hot Plug Entry 1y Wty RMKT Hard Drive | $95 | 61 |
| 484062-B21 | HP 8GB Fully Buffered DIMM PC2-6400 2×4GB DDR2 RMKT Memory Kit | $175 | 2 |
| 448193-B21 | AMD Opteron 8356 2.3GHz Quad Core DL585 G2 Processor Option RMKT Kit | $1,965 | 30 |
| 538279-001 | HP ProLiant DL165 G6 2423HE 2.0GHz Six Core Non-hot Plug RMKT Rack Server | $875 | 2 |
| 500923-001 | HP ProLiant DL585 G5 8382 2.6GHz Quad Core 4P RMKT Rack Server | $4,835 | 1 |
Factory Sealed/Refurbished/FULL HP WARRANTY!
Alliance Technology Partners is a leading reseller of HP Factory Refurbished products including Refurbished Proliant Servers, Refurbished Procurve Networking Products, Refurbished HP Notebooks, Refurbished HP Computers, Refurbished HP Workstations, and more!
MASSIVE SAVINGS ON HP DL380g6, ML350g6, AND DL160g6
HP Factory Refurbished (Renew) Proliant Servers - FULL HP WARRANTY!
491316-001 $3895 qty 18
HP DL380G6 HPM 2x QC X5550 2.66GHz 12GB 2.5″ DVDRW RPS
SAVE OVER $2000 off of list price! - Quickspecs
576778-001 $2740 qty 9
HP ML350G6 5U Xeon QC E5530 2.4GHZ 2P 12GB P410/512 DVD HPM
SAVE OVER $1900 off of list price! - Quickspecs
490455-001 $2895 qty 39
HP DL160 G6 2X X5550 2.66ghz 12GB(6×2GB) P410i/256mb BBWC
SAVE OVER $1800 off of list price! - Quickspecs
File Recovery Speed Improves by 95 Percent – Veeam Success Story
The Business Challenge
The IT team at Isaac Agnew (Holdings) Ltd chose to virtualize with VMware for the same reasons most companies do: cost and space savings. Now approximately one-third of their environment is virtualized. They operate 50 physical servers and 20 virtual machines on several VMware ESX servers. This infrastructure supports 20 sites and roughly 800 users.
Following the virtualization rollout, the IT team realized they needed a more comprehensive and reliable backup and recovery solution. In the early days of their VMware implementation, they ran a script that copied specific sections of the file system they manually chose ahead of time and synchronized them to a backup folder.
“Even though the process took a very short time because we only backed up a subset of files, it was a bit unsettling to pick and choose what we thought was most critical to save,” explained Tim Carter, the company’s Senior Systems Administrator. “And, we could only back up files, not databases.”
In addition to an inclusive and consistent backup process, Tim and his team wanted a virtualization-specific solution that would restore their virtualized data to its original state quickly, rather than requiring them to rebuild each virtual machine. “In the past, if we had to restore, we’d have to rebuild the VM completely from a template, check its configuration, restore the software, and then copy the relevant files, resulting in a lot of late night and weekend work,” he said.
“A traditional disaster recovery product was ruled out due to the cost involved. The company would have had to purchase a license for each virtual server, and also sacrifice a percentage of each server’s operating capacity to backup agents,” explained Tim.
The Veeam Backup & Replication Solution
The Isaac Agnew IT team looked at three backup solutions. Tim said they considered Veeam Backup & Replication because they were already longtime users of Veeam FastSCP, the free file management utility. “Veeam Backup is right there in the same interface we were already using, so it was a natural decision to consider it,” he said.
In the end, they chose Veeam Backup & Replication for several key reasons. “The main reason is because it offers a much better solution for restoring either the whole VM or individual files,” he said. “The other products we looked at
While backup speed is important to Tim and his team, it’s not as important as recovery speed. “When we lost a VM in the past, we would have to rebuild it completely, and seemed to offer the same thing, but in reality, they required double backups—once for the whole image, and then again for the file system. This is a big waste of time and storage space and simply didn’t fit into our tight window to perform backups each night.”
While backup speed is important to Tim and his team, it’s not as important as recovery speed. “When we lost a VM in the past, we would have to rebuild it completely, and this would take too long,” he said. “Now that Veeam Backup is in place, it’s a simple matter of right-clicking ‘restore,’ and the data is recovered in minutes—no more working nights and weekends.”Veeam Backup’s fast file-level recovery feature allows the IT team to restore individual files from the image-level backups in seconds, without having to extract the full VM image to their local drive.
A backup solution designed from the ground up for virtual servers was the right solution for Isaac Agnew (Holdings) Ltd because unlike traditional physical system backup tools that have been adapted for use in a virtual environment, Veeam Backup & Replication doesn’t require agents, which can consume a lot of system processing cycles. Instead, the Veeam product works at the hypervisor level, using the VMware API.
The Results
Backs Up Data Once, Not Twice
When Tim and his team compared virtualization backup and recovery programs, they discovered that Veeam Backup & Replication performs backups once, not twice like the others (once for the full image and then again for the file system). Veeam’s faster, more efficient process fits better into the company’s tight backup window each night.
Improves Recovery Speed by 95 percent
The previous recovery process involved Tim and his team rebuilding a VM from a template, restoring and configuring the software, and then copying the relevant files. This took multiple hours, often spilling over into the evening and weekends, which meant the company paid unnecessary overtime. Now that Veeam Backup & Replication is place, all they have to do is right-click on “restore,” and they have what they need in minutes.
Eliminates Backup Agents that Bog Down Server Performance
Traditional physical backup products deploy agents on each virtual machine, consuming precious processing resources. In addition, they require additional backup software licenses for each VM, making the expense add up quickly. Veeam Backup & Replication was designed specifically for the virtual server environment and is priced by physical CPU socket, no matter how many VMs are running.
About Veeam Software
Veeam Software, a premier- level VMware Technology Alliance Partner and member of the VMware Ready Management program, provides innovative software for managing VMware Infrastructure. Veeam offers an award-winning suite of tools to assist the VMware administrator, including #1 for VMware: Veeam Backup & Replication; Veeam Reporter Enterprise, to document virtual environments for capacity planning and chargeback; Veeam Configurator, offering complete host configuration management; and Veeam Monitor, for performance monitoring and alerting across multiple VMware vCenters. With its acquisition of nworks, Veeam’s products include the nworks Smart Plug-in and the nworks Management Pack that offer VMware monitoring and management from Microsoft and HP enterprise management consoles.
Learn more about Veeam Software by visiting www.veeam.com and learn more about Alliance Technology by visiting www.alliancetechpartners.com
Acunetix Web Vulnerability Scanner Version 7 BETA Available!
Acunetix Web Vulnerability Scanner Version 7 is available in beta, and what a version!
It has been one long year of development, testing and late nights at the office, though it was all worth it, and the results speak for themselves! Most of the core components have been rewritten, such as the crawler, scanner, vulnerability checks and the HTTP stack. Acunetix Web Vulnerability Scanner Version 7 is around 75% faster and more intelligent scanner than its predecessors. Most of the web vulnerability checks have been migrated from VulnXML format to Scripts. This allows us to have more advanced and flexible security checks, while reducing false positives. It is also easier for you to develop your own web vulnerability checks. Version 7 also includes much more meticulous web security tests, some of which were not possible before.
If you are interested in testing the new BETA of Version 7, and you already own an Acunetix WVS Enterprise or Consultant license with a valid maintenance agreement, contact us at beta@acunetix.com.
The FREE version of Acunetix WVS Version 7 BETA can be downloaded from here
The new features of Version 7 are:
- A new revolutionary and intelligent scanning engine
- Detection of a wide range of new web vulnerability types
- No more ‘brute force style’ vulnerability checks
- Consumes less bandwidth
- Less False Positives and False Negatives reported
- Website parameters are thoroughly analyzed to understand their purpose
- A Number of thorough checks are launched before vulnerabilities are reported
- Human like vulnerability verifying techniques
- Scriptable Vulnerabilities
- More flexible and advanced web security checks
- Easier to script own vulnerabilities
- Faster processing
- Consolidation of reported vulnerabilities
- Different variants of the same vulnerability are consolidated under one detailed report
- Presenting the problem to developers in a more precise and understandable way
- Facilitates prioritization and coordination of vulnerability remediation
- Advanced analysis of website presentation layer
- Less chances of breaking down a website because of a security scan
- Ability to automatically submit the correct data in web forms
- A whole variety of new vulnerability checks
- Stored SQL injection
- Stored File Inclusion
- Stored Directory Traversal
- Stored Code Execution
- Stored File Tampering
- More advanced WebDav auditing checks
- Automated form based authentication auditing (e.g. tests to check if credentials can be brute forced, for common username and passwords etc)
- Test for SQL Injection In URL
- New Scan Status Interface
- Graphical presentation of scan status
- Granular explanation of current running tasks
- Ability to capture more information at a glance
- Re-Scan capabilities
- Right click a reported vulnerability and relaunch the test
- No need to rerun a whole crawl and scan to verify fixes
- Saves time in verifying corrections
- Ability to specify label or tag instead of actual parameter name in input fields settings node
- Option to automatically randomize input for parameters specified in Input Fields settings node
- New well known web applications (e.g. WordPress) finger printing module
Major improvements in Version 7:
- Drastically improved Web 2.0 applications support
- Better handling and parsing of JSON and XML requests and responses, and other similar Web 2.0 technologies
- Improved Session Management
- Improved HTTP Sniffer / Manual crawling process
- Support for a wider variety of content-types
- Support for Web 2.0 requests and responses e.g. JSON, XML etc
- Improved network traffic handling
- Support for HTTP Keep-alive
- DNS Caching helps in reducing multiple DNS requests
- Ability to control delay between requests
- Faster handling of traffic
- HTTP Authentication
- Support for Digest HTTP authentication mechanism
- Crawler supports more than a single pair of HTTP credentials for the same host
- HTTP Authentication settings are now shared between all Acunetix WVS tools
- Granular specification of credentials (per server, directory or file)
New HTTP Authentication settings node
- Site Crawler
- Supports a wider variety of communication mechanisms
- Improved handling and detection of links and input parameters
- Faster crawling of websites
- Improved XSS Detection rate
- Improved web server security auditing techniques for source code disclosure, directory listing and directory traversal checks
- Drastically improved file upload security checks
- Improved DNS auditing scripts
- Improved security checks for old, backup files and other similar file checks
Acunetix Web Vulnerability Scanner Version 7 documentation
The Acunetix WVS Version 7 user manual is available in PDF Format and also in HTML Format.
With the introduction of scripting, a Getting Started guide / SDK is available to help you understand how the new vulnerability checks are implemented in Acunetix Web Vulnerability Scanner and to help you write your own scripts / security checks. We also developed a new tool, ‘WVS Scripting’, to help you writing your own scripts and testing them. You can download the documentation and tool from the following location; http://www.acunetix.com/download/tools/Acunetix_SDK.zip.
At a later stage, a more detailed SDK and ‘WVS Scripting’ tool documentation will also be released.
Alliance Technology Partners is a leading resellers of the Acunetix Web Vulnerability Scanner
Veeam Success Story – Backup Speed Increases by 98 Percent
Backup Speed Increases by 98 Percent at
Leading UK Pension Organization
The Business Challenge
The IT infrastructure at The Pensions Trust is 95 percent virtualized. There were nearly 35 physical servers before the VMware consolidation began, and now there are six. Four of them host 35 virtual servers, and the other two host 60 virtual desktops. With so many “eggs” in relatively few “baskets,” ensuring consistent, reliable backups of the virtual environment is especially important. Darren Bull, Business Support Manager for The Pensions Trust, and his team implemented a first-generation backup and recovery tool for the virtual servers that appeared to work for a while. “Then each revision of the product deteriorated,” he explained. “That meant we were constantly monitoring backups because they failed continually, which took a tremendous amount of extra time—both at work and into the evenings. I had to log on from home every night to check backups because they were always failing.”
The Veeam Solution
Darren and his team chose Veeam Backup & Replication to replace the previous product. “Veeam is totally brilliant,” he explained. “To start, it’s much faster than what we used to use. I can back up the 800 GB main !le server in 10 minutes; the other backup system took eight to nine hours to do the same job, if it worked at all.” While backup speed is important to Darren and his team, reliability is even more important. “I simply cannot believe how much di”erence there is between the two products, especially with regard to reliability. I used to spend countless hours monitoring and manually troubleshooting the old system because it continually failed. However, now that we use Veeam Backup & Replication, we all feel like a huge weight has been lifted.” Veeam Backup & Replication also requires less backup storage space than the previous product. “There was no ‘self-cleaning’ with the other product, which meant we had to clean down the !le system each week—a process that could take seven to eight hours—and we could only do this on a Sunday when no backups ran,” Darren said. “Not only was this a laborious process, but it hardly freed up any space. Veeam uses almost half the space (55 percent compared to 98 percent with the other product), and no manual intervention is required. That’s a massive di”erence.” Another major di”erence between Veeam Backup & Replication and the previous product is customer support. “Veeam is a breath of fresh air,” Darren said. “I !nd Veeam support to be very helpful because people actually answer my questions and don’t tell me to wait for the next version. I also like the Veeam forums, which include many contented customers because they did exactly what we did: they made the switch to Veeam.”
The Results
Increases backup speed by 98 percent – With Veeam Backup & Replication, Darren and his team can back up the main file server (800 GB) in 10 minutes. It used to take eight to nine hours with the previous backup product.
Ensures consistent and reliable backups – The IT team used to spend countless hours monitoring and manually troubleshooting the previous backup product because it continually failed. This included nights and weekends. Now that the team uses Veeam Backup & Replication, they feel like a huge weight has been lifted.
Requires much less space for backup storage – Veeam Backup & Replication uses almost half the backup storage space (55 percent) compared to the previous product (98 percent).
Veeam Software, a premier-level VMware Technology Alliance Partner and member of the VMware Ready Management program, provides innovative software for managing VMware vSphere 4 and Virtual Infrastructure 3. Veeam o”ers an award-winning suite of tools to assist the VMware administrator, including #1 for VMware backup: Veeam Backup & Replication; Veeam Reporter Enterprise, for VMware performance, storage, capacity reporting and chargeback; Veeam Monitor, for VMware performance monitoring and alerting across multiple vCenters; and Veeam Business View, a free add-on that works with other Veeam products to provide business categorization for the VMware vSphere environment. With its acquisition of nworks, Veeam’s products include the nworks Smart Plug-in and the nworks Management Pack that incorporate VMware data into enterprise management consoles from HP and Microsoft. Learn more about Veeam Software by visiting Alliance Technology Partners, a Veeam Gold ProPartner
HP Renew Proliant Server Hard Drives – 516814-b21, 516816-b21, 516828-b21
Factory Sealed/Refurbished/FULL HP WARRANTY!
516814-b21 HP 300GB 15K 6G Hot-Swap 3.5″ SAS qty 17 $435ea
516816-b21 HP 450GB 15K 6G 3.5IN DP SAS HD qty 16 $475ea
516828-b21 HP 600GB 15K 6G Hot-Swap 3.5″ SAS-2 Dual Port qty 35 $530ea
Factory Sealed/Refurbished/FULL HP WARRANTY!
Alliance Technology Partners is a leading reseller of HP Factory Refurbished products including Refurbished Proliant Servers, Refurbished Procurve Networking Products, Refurbished HP Notebooks, Refurbished HP Computers, Refurbished HP Workstations, and more!
507782-b21 – $1295! – HP BL460C G6 E5520 2.26ghz 6GB(3×2GB) P410i
507782-B21 – $1295 – HP BL460c Blade Server
507782-B21 – $1295
HP BL460C G6 E5520 2.26ghz 6GB(3×2GB) P410i
(Factory Sealed/Refurbished/FULL HP Warranty)
Factory Sealed/Refurbished/FULL HP WARRANTY!
Alliance Technology Partners is a leading reseller of HP Factory Refurbished products including Refurbished Proliant Servers, Refurbished Procurve Networking Products, Refurbished HP Notebooks, Refurbished HP Computers, Refurbished HP Workstations, and more!
VMware Management for Service Providers by Veeam
#1 Data Protection and Disaster recovery for VMware Cloud and Service Providers
Service and VMware vCloud providers offering hosting services to customers face challenges of managing a multi-tenant VMware environment. They must protect all virtual machines in the cloud, meet different SLAs and, at the same time, keep costs low. Veeam Service Provider Program designed specifically for VMware vCloud and VMware hosting providers can help you:
1. Protect all VMs with ONE solution
2. Increase revenue by providing additional service offerings
3. Reduce hardware and software costs
Real business outcomes with innovative solutions from Veeam Software
Virtualization creates opportunities for service providers to offer new services, and provides the foundation for cost savings and greater profitability. However, existing VMware management tools are not well aligned with service providers’ needs and business model.
To fill this gap, Veeam offers its solutions through a program designed specifically for service providers. With data protection and virtual infrastructure management from Veeam, you can enhance the manageability of your VMware data center environment and extend hosted offerings around VMware.
Business-focused management
Managing a dynamic, multi-tenant VMware environment is not easy. You need to ensure all resources are efficiently used, even while demand is fluctuating. At the same time, you must meet service level agreements (SLAs) and keep costs low.
Most management tools for VMware only offer an IT-centric view of your virtual infrastructure and do not allow virtual resources to be managed or prioritized by business needs—for example, by customer or by SLA—which makes analysis and management difficult. Can you tell which virtual machines (VMs) customers are actually using during a billing period? Are there orphaned VMs that should be decommissioned? Can you monitor VMs and escalate issues according to SLAs? With Veeam Business View, you can align management of your virtual infrastructure with the constructs of your business. Veeam Business View works in conjunction with other Veeam products to allow you to view and manage VMs from a functional or business standpoint, not just a technical standpoint.
Report on performance or resource usage by customer
Veeam Reporter provides unparalleled reporting on your virtual infrastructure, with both technical and business perspectives on configuration and usage. Learn to whom VMs belong and ensure this correlates with your current customer database. Keep track of resources, analyze storage consumption, and generate reports for health checks, chargeback analysis, capacity planning and auditing.
Deliver on SLAs
Meet and exceed service levels with business-focused monitoring and alerting. With Veeam Monitor, you can proactively monitor VMware infrastructure from a traditional IT-centric view, or according to SLAs, customers, or any other category you define.
Monitor everything from a single console
Get a business-oriented and cohesive view of your physical and virtual environment—and the applications and services running there—with Veeam. If you have Microsoft System Center Operations Manager or HP Operations Manager, Veeam protects your investment in those monitoring systems with the nworks Management Pack and the nworks Smart Plug-in. Publish VMware performance data and VMware vCenter events directly to your existing Microsoft or HP console, unify management of your physical and virtual resources, and free your VMware administrators from routine fire-fighting and troubleshooting.
Virtualization-Powered Protection
Availability and data protection are top of mind for customers going to the cloud. When choosing a service provider, backup options are often a prime consideration. Veeam provides the most robust solution for data protection with Veeam Backup & Replication, which allows you to create tiered SLAs and extend the scope of backup and recovery services. Deliver improved RPOs and RTOs by leveraging advancements in VMware vSphere and vStorage, Veeam Backup & Replication provides much faster backup cycles—up to 10 times faster for incremental backups and up to 5 times faster for full backups. This means you can back up customer data more often—for example, once an hour instead of once a day—and improve recovery point objectives (RPOs). And with streamlined and granular recovery, you can also improve recovery time objectives (RTOs). Offer extra protection with near-CDP With this feature, you can offer 24×7x365 availability with a near-zero RTO and a 5-minute RPO. Veeam Backup & Replication updates VM replicas as often as every 5 minutes, providing near-continuous data protection. And because many VMs can be replicated to a single inexpensive host, you can provide this level of protection at a fraction of the cost of traditional CDP.
Restore individual files and folders
Veeam allows you to instantly recover files from Windows and Linux VMs both to the latest state, or to a specific point in time. And it doesn’t require restoring the entire VM image. Imagine the competitive differentiation or premium service you can offer with this capability.
Automate it!
With the Veeam SDK you can integrate Veeam Backup & Replication into your
existing workflow and increase the productivity and efficiency of data protection
and restoration activities.
Reduce storage cost
Veeam Backup & Replication implements data compression and inline deduplication
to minimize storage costs and network traffic. Deduplication and compression,
along with synthetic backups and white space removal, allow you to reduce
storage consumption by up to 80%.
Call our Virtualization hotline to talk to an Alliance expert or sign up now for the Veeam Service Provider Program
888-891-8885 option 1


