• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Question Suspicious visits to the website

Piekielko

Basic Pleskian
Server operating system version
Ubuntu 18.04.6 LTS
Plesk version and microupdate number
18.0.48
How is it that someone accessed my website using their own independent domain? This is the second time I found a similar problem in the logs. Earlier, I noticed the ca4mps.cf domain. What could be wrong?

Access Apache logs:
79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"
66.249.66.69 - - [30/Nov/2022:12:52:26 +0100] "GET /etniczne/bizuteria/przedbajkalscy-buraci HTTP/1.0" 200 18286 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +What Is Googlebot | Google Search Central | Documentation | Google Developers)"
103.225.200.236 - - [30/Nov/2022:12:52:26 +0100] "GET /kontakt HTTP/1.0" 200 19386 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
 

Attachments

  • screen.png
    screen.png
    38.6 KB · Views: 6
I think you are misinterpreting the log. The URL highlighted in bold in the log entry below indicates a Referer. I.e "The address from which a resource has been requested". So your websites hasn't been accessed via this URL, but rather has been requested from this URL.

79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"

More info on apache log formatting that might be useful to understand the log content: How to View & Analyze Apache Access & Error Log Files - Sematext

I am not familiar with Joomla, so I have no idea how it got in your sites cache. Seems a bit strange to me, but I am not sure.
 
Yes, you are right. I guess I was a little too nervous. But all the time I am surprised how this domain was saved in the cache as the displayed home page??. :-/
 
Back
Top