• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Strange FTP connections

1

19media

Guest
I'd really appreciate the knowledge and help of some slightly more experienced linux users...

Logwatch is showing a large number of attempted FTP logins to a particular domain on our server from a wide range of IPs from all over the world. The attempted logins are all to the same username (which was until recently a valid username).

We changed the ftp usernames and passwords on the server before backing-up and reimaging, so the logs only go back a couple of days.

We keep the FTP ports closed on a hardware firewall, but whenever any of the three (valid) users open the port to upload or download, the secure log fills up with attempted FTP connections from IPs all over the place.

What sort of things should I be looking at to trace the root of this problem?
 
Back
Top