• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Much access to login page

Nebraska

New Pleskian
Hi guys!

I checked my /usr/local/psa/admin/logs/httpsd_access_log today and saw that for many months there is access to the login page each few seconds. Mostly by the same IPs. So I guess they are trying to brute force my password. In this log file I only see the GET data, so I don't know which passwords they try (passwords are transmitted via POST data). Is there an other log file where I can see all successful logins that I can check if anything serious happened?
And how do I prevent such IPs to brute force my password? For example it would be cool if I could ban all IPs automatically which tried five times with a wrong password to login.

Thx!
 
What about Home>Settings>IP access restriction management?
 
Okay, so I'd have to add all those IPs which try to brute force me. Can this be done automatically?
And what about a log of all successful logins?
 
What about Home>Settings>IP access restriction management?

I tried that with a friend. So I set his IP on the black list but he still has normal access to the login page and still is able to try to login. So IP access restriction management doesn't work at all.
After his tries to login in I checked out /usr/local/psa/admin/logs/httpsd_access_log and saw exactly the IP I set on the black list. This really confuses me.
 
Back
Top