• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Inviting everyone to the UX test of a new security feature in the WP Toolkit
    For WordPress site owners, threats posed by hackers are ever-present. Because of this, we are developing a new security feature for the WP Toolkit. If the topic of WordPress website security is relevant to you, we would be grateful if you could share your experience and help us test the usability of this feature. We invite you to join us for a 1-hour online session via Google Meet. Select a convenient meeting time with our friendly UX staff here.

plesk getting hacked again and again

F

faiquet

Guest
Hi,
My plesk has got hacked 3 times after 3 reinstalls of windows server 2003 standard x64bit with plesk 9.5.5

my website content uses SSI (server side include)

Daily somehow hacker injects a iframe in every page of the server. Interesting part is if i access the html files from c:/inetpub/vhosts/ OR from the FTP all files are clean but when the url is requested from port 80 www the iframe gets included in top of the pages.

I have scanned my system for any virus/keyloggers and have also used different passwords on each reinstall but still it is happening daily.

Please guide me what can be happening and where is this iframe which is being included in every page.
 
NOTE:-

As a testing i have uploaded BLANK files in my server ftp and accessed them from www url

PHP = OK - Blank page comes and nothing included
JS = OK - Blank page comes and nothing included


ASP = iframe included automatically
HTML = iframe included automatically
HTM = iframe included automatically
SHTML = iframe included automatically

I am waiting for a reply before os reinstall since i know this will happen again next day after a full system format.
 
Back
Top