Account hack - request to review logs to ensure no malicious data was moved onto the server

Server Version#:
Player Version#: I can’t provide either because i’ve shut the server off

HI! I’ve been just notified someone logged into my server from an android device - i managed to rush home to change password, but the hacker had access to my server for at least 20 minutes.

I’ve saw some attempts at getting an update downloaded in the logs, so I thought it would be wise to request someone who knows more about how Plex on a Synology can be hacked to take a look.

22:36 the guy from UK logged into my account from apparently:

  • Device: Plex for Android (Mobile)
    Then at 22:53 he changed the password, but i managed to change it back just minute later and turn on 2FA

Should I be worried about lines like these:
May 19, 2022 22:53:27.930 [0x7fd05978cb38] DEBUG - MyPlex: updating with 44 access tokens
May 19, 2022 22:53:27.936 [0x7fd05785cb38] DEBUG - [MediaProviderManager] HTTP requesting GET Sign In | Plex

Full log from the moment he got in to the moment i kicked him out and turned off the synology NAS completely:

Did you change the password back, or did you change it to a new random password?

2FA is good.

Did you also check Sign out connected devices after password change?

To a completely new randomly generated password, yes.

Obviously i logged everyone out. I think i saw a new user added but no libraries shared to him, left him in for now, will remove him later after i boot up plex

1 Like

Logs does not indicate anything special, in the timeframe that your log covers

When said, it looks like your PMS is outdated, and a version before 1.25.3.5385-f05b712b6

Please update ASAP, since we did put in some security improvements in 1.25.7.5604
See: Plex Media Server - #490 by Ridley

Also note, that I did a lookup on your account email address, and it shows at https://haveibeenpwned.com/

So if you shared password among different places, then that could explain it

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.