• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

plesk 8.6 hacked? random sites created

N

nephilimhell

Guest
hello,
i've just got the plesk login to a new and fresh server with plesk 8.6 for Centos on it,
and after the first login i discovered a random created client and website

i've deleted and added my own client
+ i added the first hosting under that client

just an hour later! i discover again a new web is created, this time under my created client

the name of the web is giusucms.dgusdn.coim.es.md, no limits are entered, and all the services are checked (apache asp, ssi, php, ...) an ftp user is created and shell access to server is set to /bin/tcsh!

how can this be accomplished?
 
well, i'm trying to do that,
but when i go to Server => Administrator information and click Change password,
i keep getting the message: Error: Unable to change the administrator's password: old password is incorrect. Please, try again.

although i enter there the password i use to login to plesk (the username i got from my provider we requested the dedicated server is root)
 
Back
Top