• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Much access to login page

Nebraska

New Pleskian
Hi guys!

I checked my /usr/local/psa/admin/logs/httpsd_access_log today and saw that for many months there is access to the login page each few seconds. Mostly by the same IPs. So I guess they are trying to brute force my password. In this log file I only see the GET data, so I don't know which passwords they try (passwords are transmitted via POST data). Is there an other log file where I can see all successful logins that I can check if anything serious happened?
And how do I prevent such IPs to brute force my password? For example it would be cool if I could ban all IPs automatically which tried five times with a wrong password to login.

Thx!
 
What about Home>Settings>IP access restriction management?
 
Okay, so I'd have to add all those IPs which try to brute force me. Can this be done automatically?
And what about a log of all successful logins?
 
What about Home>Settings>IP access restriction management?

I tried that with a friend. So I set his IP on the black list but he still has normal access to the login page and still is able to try to login. So IP access restriction management doesn't work at all.
After his tries to login in I checked out /usr/local/psa/admin/logs/httpsd_access_log and saw exactly the IP I set on the black list. This really confuses me.
 
Back
Top