• We value your experience with Plesk during 2025
    Plesk strives to perform even better in 2026. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2025.
    Please take this short survey:

    https://survey.webpros.com/

Spam - How are they getting to /tmp

whnunlife

New Pleskian
So I was running top, and noticed that one of my domains, had many perl scripts running. After doing a perl script scan, I found that they somehow upload a file and extracted it.

This is the path:

/tmp/.picl/st

Within this folder, there are the following:

eb.php
in
index.html
ini.inc
in.txt
list.txt
ms
msg.txt
send.pl
users

and a few other files.

So, after I remove this entire folder, how can I make sure that this does not happen again?
 
Back
Top