• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Please beaware of a breaking change in the REST API on the next Plesk release (18.0.62).
    Starting from Plesk Obsidian 18.0.62, requests to REST API containing the Content-Type header with a media-type directive other than “application/json” will result in the HTTP “415 Unsupported Media Type” client error response code. Read more here

plesk getting hacked again and again

F

faiquet

Guest
Hi,
My plesk has got hacked 3 times after 3 reinstalls of windows server 2003 standard x64bit with plesk 9.5.5

my website content uses SSI (server side include)

Daily somehow hacker injects a iframe in every page of the server. Interesting part is if i access the html files from c:/inetpub/vhosts/ OR from the FTP all files are clean but when the url is requested from port 80 www the iframe gets included in top of the pages.

I have scanned my system for any virus/keyloggers and have also used different passwords on each reinstall but still it is happening daily.

Please guide me what can be happening and where is this iframe which is being included in every page.
 
NOTE:-

As a testing i have uploaded BLANK files in my server ftp and accessed them from www url

PHP = OK - Blank page comes and nothing included
JS = OK - Blank page comes and nothing included


ASP = iframe included automatically
HTML = iframe included automatically
HTM = iframe included automatically
SHTML = iframe included automatically

I am waiting for a reply before os reinstall since i know this will happen again next day after a full system format.
 
Back
Top