LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-08-2015, 01:01 PM   #16
ntubski
Senior Member
 
Registered: Nov 2005
Distribution: Debian, Arch
Posts: 3,780

Rep: Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081Reputation: 2081

Quote:
Originally Posted by mike2010 View Post
my server tech support says it's all normal. go figure.
If the server rebooting all the time is normal, you should probably look for a different server.

But maybe they meant login from 127.0.0.1 is normal, in which case it seems they are correct: http://kb.odin.com/en/119663

Quote:
Question

I see several active admin sessions on localhost with address 127.0.0.1. Does it mean that somebody else is logged on Plesk server?

Answer

This is expected behavior. You can watch the active localhost admin sessions during daily maintenance script usually. The process runs as Plesk administrator ('psaadm' system user) and perform maintenance tasks.
 
Old 04-08-2015, 03:31 PM   #17
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by mike2010 View Post
these forums are about as helpful as a $3 bill.
and with that comment, I won't be helping you out any more.

Bitch about free help from Volunteers. Talk about ungrateful.

http://www.plesk.com/support/
 
Old 04-08-2015, 03:59 PM   #18
mike2010
Member
 
Registered: Jan 2009
Posts: 132

Original Poster
Rep: Reputation: 15
thoughts on blocking 0.0.0.0 ?

Quote:
Originally Posted by Habitual View Post
and with that comment, I won't be helping you out any more.

Bitch about free help from Volunteers. Talk about ungrateful.

not to u , bro...just some of the others.
 
Old 04-08-2015, 04:18 PM   #19
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
You need to step back and take a deep breath... no humor intended.

No one is logging in from 127.0.0.1 - that address is not visible - at all - from the outside.

Many machine processes will use 127.0.0.1 for various purposes - but not for login.

But when people have asked for more info, just saying that it reboots due to a login to 127.0.0.1 is totally unhelpful and uninformative. On the other hand, you undoubtedly think that is the major cause of the problem.

So, could you explain a little more precisely, with some actual messages or log lines that lead you to that conclusion. Perhaps that will allow us to understand why you have reached that conclusion and lead to a resolution.
 
Old 04-08-2015, 04:29 PM   #20
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled

Restricting Administrative Access


Good bye and good luck.
 
Old 04-09-2015, 05:40 PM   #21
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by mike2010 View Post
still just creepers.. (wankin off and laughin like little jerkoffs in the background..probably)
Frustrated you may be but still some of your language in this thread is not acceptable.
So I'm warning you (in a friendly way) you should mind both your tongue and attitude.
Thanks in advance.
 
Old 04-10-2015, 05:04 AM   #22
mike2010
Member
 
Registered: Jan 2009
Posts: 132

Original Poster
Rep: Reputation: 15
sowwyyy.
 
Old 04-18-2015, 07:18 PM   #23
Hb_Kai
Member
 
Registered: Jan 2008
Distribution: Windows 8.1, Debian 7
Posts: 91

Rep: Reputation: 49
I don't personally use Plesk but usually, especially when in concern of hackers, one of the best places to look is in the logs.
http://kb.modularmerchant.com/how-to...plesk-a656.php

Consider taking a swift peak through the following files; you may find something there:

/usr/local/psa/admin/logs/httpsd_access_log
/var/log/sw-cp-server/error_log

/var/www/vhosts/domain.com/logs/error_log
/var/www/vhosts/domain.com/logs/access_log

/var/log/httpd/access_log
/var/log/httpd/error_log
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Plesk throttling web traffic - Centos 6.4 - Plesk 11.5 imadsani Linux - Server 9 01-29-2014 02:35 PM
connect to 127.0.0.1[127.0.0.1]: Connection refused (port 10024) adamos22 Linux - Newbie 2 07-31-2013 12:40 PM
psad: scan detected: 127.0.0.1 -> 127.0.0.1 tcp macaal Linux - Security 4 06-17-2011 01:56 PM
Sendmail : relay=[127.0.0.1] [127.0.0.1], dsn=4.0.0, stat=Deferred: Connection refuse macadam Linux - Software 0 09-23-2007 02:44 PM
DSN: Data format error & relay=[127.0.0.1] [127.0.0.1] calmbomb Linux - Software 0 11-07-2004 03:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration