I
InterJinn
Guest
A plesk enabled server I manage has been breached several times in the past few weeks. Everytime (that I can see via Plesk logs) the breach has come in through the Plesk management interface. I don't know how it is occurring but I have changed passwords and they are still able to access the plesk management interface. The hacker connects form many different IPs and always sets the account info to Name: Arber, email: [email protected]. When he connects he completely purges existing domains, then creates his own warez domain and uploads software to it. At any rate even after locking down FTP and SSH he still can access the Plesk interface. I have disabled the psa service (service psa stop) and disabled it from the startup options (chkconfig psa off). This disables Plesk sort-of. Unfortunately Plesk then presents a Plesk diagnostics page the following information:
Problems found:
The Plesk control panel service is switched off.
Solutions:
Restart the Plesk control panel service.
The SMTP server service is switched off.
Solutions:
Restart the SMTP server service.
[ Apply Selected Solutions ]
When I click the button somehow the system bypasses the psa service and starts up some stuff. This re-enables the plesk interface and thus makes disabling the service futile. Please tell me how I can prevent Plesk access to my server. I want to be able to turn on Plesk when *I* want to do configuration and leave it off otherwise. Shedding some light on how the attacker is getting into my control panel would also be nice since I've changed the passwords and each time they are able to regain access and relatively easily considering the time delay between re-access.
Thanks,
Rob.
Problems found:
The Plesk control panel service is switched off.
Solutions:
Restart the Plesk control panel service.
The SMTP server service is switched off.
Solutions:
Restart the SMTP server service.
[ Apply Selected Solutions ]
When I click the button somehow the system bypasses the psa service and starts up some stuff. This re-enables the plesk interface and thus makes disabling the service futile. Please tell me how I can prevent Plesk access to my server. I want to be able to turn on Plesk when *I* want to do configuration and leave it off otherwise. Shedding some light on how the attacker is getting into my control panel would also be nice since I've changed the passwords and each time they are able to regain access and relatively easily considering the time delay between re-access.
Thanks,
Rob.