• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Resolved web site hacks

klockstone

New Pleskian
I've come across 2 holiday accommodation web sites that seem to be compromised by gaming equipment ads. To see this, Google on 'Malston Mill' and 'Dittiscombe'. Both have the correct link in to their sites, but short description is nothing to do with them. Click on the 3 dots and you'll see their caches have been taken over by the advert.

Does anyone know how this exploit works and if the Plesk system is resistant? How do you get rid of this?

Duckduckgo and Mojeek don't seem to have the same problem.

Keith Lockstone
 
I see no indication that those websites are running on a server with Plesk, they appear to be running on servers with a different control panel.
So Plesk most likely has no relation to those websites.
Note: Both websites are running with Wordpress so the hack was very likely made through outdated/insecure Wordpress installations and/or plugins.
 
I looked at the source and Malston Mill seems to be running WordPress 4.9.22 and Dittiscombe WordPress 5.6.10. Both have been compromised.

I've notified both (I know one of the owners) but have had no reply so far.
 
Back
Top