• We value your experience with Plesk during 2025
    Plesk strives to perform even better in 2026. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2025.
    Please take this short survey:

    https://survey.webpros.com/

Server generating DDoS Attacks

AndyJUK

New Pleskian
Hi All

I have a dedicated server with 1and1 which is running:

OS Linux 2.6.18-194.26.1.el5
Panel version 10.4.4
Update #49, last updated at April 14, 2013 04:04 AM

For the last 3 weeks, the site gets shut down by the data centre, usually on a Thursday evening because it's found to be running DDoS attacks. I bring the server back online and each week I have cleared off some old sites including ones where clients have installed Wordpress and not updated. What I've found shows that this seems to be the point of entry.

However, I've looked through logs and things and I can't see anything obvious. That could well be because I don't know what I'm looking for.

1and1 can't or won't help. They won't look even though I offered to pay and they can't recommend a company that can look for me. So, their suggestion is to go out to an unknown world with a compromised server and ask for help.

Could someone point me in the right direction, please as this is driving me to insanity.

I'm guessing that the WP exploit has let someone place files in a directory outside any of the /var/www/vhosts/[site] structure as I've deleted the sites completely that were using WP.

But I haven't got a clue where to start looking from here.

RK gives some warnings but I've searched and these look like false positives.

So, that's where I am!

Best regards
Andy
 
Have a chat with the guys at Atomicorp (www.atomicorp.com).

They are security experts and may be able to find the problem. I can't say for sure if they will be able to offer you the kind of service you need(i.e. find an existing compromise) mind you. But they do offer a product that will help prevent future compromises though, in the form of ASL.

No, I don't get a commission. But I do use ASL and would not set up a public-facing hosting server without it. But that's my cautious character showing :)
 
Back
Top