• The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Server generating DDoS Attacks

AndyJUK

New Pleskian
Hi All

I have a dedicated server with 1and1 which is running:

OS Linux 2.6.18-194.26.1.el5
Panel version 10.4.4
Update #49, last updated at April 14, 2013 04:04 AM

For the last 3 weeks, the site gets shut down by the data centre, usually on a Thursday evening because it's found to be running DDoS attacks. I bring the server back online and each week I have cleared off some old sites including ones where clients have installed Wordpress and not updated. What I've found shows that this seems to be the point of entry.

However, I've looked through logs and things and I can't see anything obvious. That could well be because I don't know what I'm looking for.

1and1 can't or won't help. They won't look even though I offered to pay and they can't recommend a company that can look for me. So, their suggestion is to go out to an unknown world with a compromised server and ask for help.

Could someone point me in the right direction, please as this is driving me to insanity.

I'm guessing that the WP exploit has let someone place files in a directory outside any of the /var/www/vhosts/[site] structure as I've deleted the sites completely that were using WP.

But I haven't got a clue where to start looking from here.

RK gives some warnings but I've searched and these look like false positives.

So, that's where I am!

Best regards
Andy
 
Have a chat with the guys at Atomicorp (www.atomicorp.com).

They are security experts and may be able to find the problem. I can't say for sure if they will be able to offer you the kind of service you need(i.e. find an existing compromise) mind you. But they do offer a product that will help prevent future compromises though, in the form of ASL.

No, I don't get a commission. But I do use ASL and would not set up a public-facing hosting server without it. But that's my cautious character showing :)
 
Back
Top