• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Inviting everyone to the UX test of a new security feature in the WP Toolkit
    For WordPress site owners, threats posed by hackers are ever-present. Because of this, we are developing a new security feature for the WP Toolkit. If the topic of WordPress website security is relevant to you, we would be grateful if you could share your experience and help us test the usability of this feature. We invite you to join us for a 1-hour online session via Google Meet. Select a convenient meeting time with our friendly UX staff here.

Suspicious sys0972500-1.php inside httpdocs/

Andrew_Pa

Regular Pleskian
Before 2 days I found inside the httpdocs a new folder which name was css. Inside this folder I found a file named sys0972500-1.php , which it caused send thousands spam emails from my server.

I deleted it and today I had the same problem.

The website I have inside the httpdocs is joomla, which I have updated to the newest version and also I updated the templates.

I also changed the ftp password.

I found on the net another guy with the same problem but he didn't find a solution.

You can find the code which was inside the suspicious file by clicking the link : http://pastebin.com/NbyT5wfF

I have many domains on my Plesk Server, but this "hack" appears only in one of them.

How prevent from writing files on httpdocs?

Also I already changed all the permission of the folder and files (inside httpdocs) from ssh.

Thank you in advance
 
Hi Andrew Pa,

sadly, this is a public bug in Joomla, which is being caused of a sadly written code.
Thus, this is a forum to Parallels products, and I think, no one could give you a shot.

But I can give you some tips:

Change the FTP-Password, upgrade your Joomla asap, and check all added extensions for updates.

We had the same problem, and the bug was in the core of joomla...
If you need assistance, give me a PM.
 
I hope that you have read already this article http://kb.parallels.com/en/114620 and applied all recommendations.

Thank you very much Igor for the suggestions! I read all of them and I try to apply them!

Hi Andrew Pa,

sadly, this is a public bug in Joomla, which is being caused of a sadly written code.
Thus, this is a forum to Parallels products, and I think, no one could give you a shot.

But I can give you some tips:

Change the FTP-Password, upgrade your Joomla asap, and check all added extensions for updates.

We had the same problem, and the bug was in the core of joomla...
If you need assistance, give me a PM.

Thank you so much my friend for the reply! I know that was from joomla but I was need a confirmation. This site isn't mine. But as Administrator of the server I should check why the problem appears.

Thank you very much for your help!
 
Dear Andrew Pa,

but it is your server, thats right? Then you should enable the log to get all php mail() commands to be informed, if another bug is being used.
You can send me an PM at any time, as I will assist you as I can for free.
 
Dear Andrew Pa,

but it is your server, thats right? Then you should enable the log to get all php mail() commands to be informed, if another bug is being used.
You can send me an PM at any time, as I will assist you as I can for free.

I have already disable the php functions for email. I check with a script and you cannot send email from this domain using php. Also I have disabled python and perl and I ave disabled the email. But the domain still send thousand emails because of this script. I think is joomla problem and not server side problem. I sent you PM!

Thank you very very much for one more time!
 
Back
Top