Plex server possibly accessed by someone else

Server Version#: latest
Player Version#: latest

Just wondering if there is a log for streams being ended or access in general.

I think someone had access to my sever as I got an odd message last night.

In the middle of a show I was watching, the stream was ended as if I (admin) ended the steam via plex dashboard. Without any message.

Then awhile later it happened again, this time with a rather odd message from someone.

I have since changed my password on Plex but wondering how someone would have gained access like that…

Do you run Tautulli, and if so is it exposed to the Internet with a weak password?

If you are still running Tautulli, make sure that the web interface is not accessible from the internet.

It also appears that you are using (or have used once) a ton of 3rd-party apps & tools. Any of them could leak your token in the case of a bug or security breach.
If you used one of these tools, but don’t anymore, revoke their access tokens here https://app.plex.tv/desktop#!/settings/devices/all
and make sure they don’t run anymore.
(careful to not revoke the tokens of you server, or you’ll have to restore your access with some effort)

Yeah that makes perfect sense.

Definitely some old plugins and 3rd party stuff in there,. Likely the source of this.

Tried accessing the link.

Permission was sorted first time but now it’s showing

403 Permission Denied

Invalid Account

Oops, sorry! I’ve corrected the link above.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.