• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

MySQL Admin Account vanished???

K

knocx

Guest
This morning i had found one of our servers PLESK login returning error like ;

Unable to connect to database: saved admin password is incorrect. 0: /usr/local/psa/admin/auto_prepend/auth.php3:66 psaerror(string "Unable to connect to database: saved admin password is incorrect.")

i had tried to reset the password but i realized that there were no users named admin.


we had audit the server and couldnt find any compromise signatures.

This is also interesting that if some one can found a way of priviledged access yo MySQL why on eath he would delete the user admin? Since after deletion he would not be able to access any mySQL relevant sources like PLESK , he could have logged in with this password...,

Since this is an interesting problem and i had read similar post on the forum i wanted to share my experiences with you

Any ideas comments are appreciated :)


-- knocx
 
Originally posted by knocx
This is also interesting that if some one can found a way of priviledged access yo MySQL why on eath he would delete the user admin? Since after deletion he would not be able to access any mySQL relevant sources like PLESK , he could have logged in with this password...
But if someone did already break in, if they wanted information, they probably already got it, then deleted the admin account to wreak havok on your server, and of course your hosted domains.
 
i dont know .... i noticed 4-5 posts similar to ours, they also dont report any attack signatures.
 
Back
Top