• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

Server stopped working

alexrockgroup

New Pleskian
Running plesk 12.5.30 on centos.

My server started having really strange problems last night that I have no idea what is causing it, or how to fix it.

The server company has been no help at all, so any advice would be appreciated.

The websites will resolve intermittently, but right now is mostly not working.

The server is running plesk, but somehow showing errors with the cpanel logo at this url /cgi-sys/defaultwebpage.cgi

Is it possible that another server is assigned the same ip as my server, that is how it seems.

I'm also getting a warning about a possible man in the middle attempt when trying to ssh in. I haven't connected while it gives that warning, and it seems to coincide with the cpanel error.

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed. The fingerprint for the RSA key sent by the remote host is SHA256:***********************. Please contact your system administrator. Add correct host key in /home//.ssh/known_hosts to get rid of this message. Offending RSA key in /home//.ssh/known_hosts:2 remove with: ssh-keygen -f "/home//.ssh/known_hosts" -R 199.217.118.27 RSA host key for *** has changed and you have requested strict checking. Host key verification failed.
 
I suggested that to the server company, but as I've said they haven't been helpful. They finally responded and said they think it is a configuration problem, but we haven't changed anything with the configuration. Is it possible that someone hacked us and is doing this maliciously? If so, how would I proceed?

I just tried using arp-scan to see if there is an ip conflict, but it didn't seem like it when I tried... but I, of course, was only able to try it when there was no problem and I was able to connect through ssh.

I thought maybe someone in the community could offer guidance on how to troubleshoot this, and since this is a plesk install, if someone had experienced a similar issue using plesk before, they might have some insight.
 
Back
Top