• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

domain hacked?

A

ACID25

Guest
Hi

on one of ouer servers we saw today ther load average is higher then normal. So we checked how could it happen and figure out that one domain must have a security hole
Code:
  748 ?        S      0:00 sh -c (sleep 99999999999999;killall -9 udp) & CONSOLE=/dev/console SELINUX_INIT=YES MYSQL_UNIX_PORT=/var/lib/mysql/mysql.sock TERM=linux 
PERL5LIB=/usr/local/psa/lib/perl5/site_perl/5.8.3:/usr/local/psa/lib/perl5/site_perl/5.8.3/i386-linux-thread-multi OLDPWD
=/var/www/vhosts/sfachim.de/httpdocs INIT_VERSION=sysvinit-2.85 PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/X11R6/bin runlevel=3 RUNLEVEL=3 PWD=/tmp 
LANG=en_US.UTF-8 previous=N PREVLEVEL=N PSA_RUN_MODE=1 SHLVL=7 OPENSSL_CONF=/usr/local/psa/admin/conf/openssl.cnf _=/usr/bin/perl
but we could not excalty figure out how it works....maybe anybody can explain we what happens there and how could we close this???

THX and best regards
ACID25
 
Hi


yes the domain was hacked through a unsecure php script...

regards
ACID25

thread can be closed!
 
Back
Top