• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question Backup FTP Storage Security

WebHostingAce

Silver Pleskian
Hi,

I hope to migrate to Vultr Hosting. As I know they offer Daily Snapshot but only one and only you can restore the whole server.

I just want to know, If I'm backing up my server daily and upload to a external FTP Storage,

In worst case scenario, if hackers get into my server would they be able to get the username and password for backup FTP Storage server as well?

Thank you
 
The hacker can see the username by looking at the BackupsSettings table of the psa database, but he will not be able to see the password, because neither the FTP account password, nor the backup encryption password is stored in plain text. Both are encrypted. If a hacker manages to access your server, the maximum the hacker can find out is the name of your FTP backup server and the name of the user account that is used for login.

But note, that a hacker who gains root access can install a software that intercepts FTP transactions. So the hacker will be able to connect to your backup account without actually knowing the password. He might not be able to access your FTP backup server immediately after breaking into your server, but he will be able to access the account next time the automatic backup is done. So it is not perfectly safe to have the external FTP backup. You'd need a backup of the backup, too, which should be controlled separately from Plesk.
 
Thank you..

Much appreciated!

What would be the best way to have a backup? I just dont want to loose all the data server and ftp backup server both.
 
Back
Top