• Hi, Pleskians! We are running a UX testing of our upcoming product intended for server management and monitoring.
    We would like to invite you to have a call with us and have some fun checking our prototype. The agenda is pretty simple - we bring new design and some scenarios that you need to walk through and succeed. We will be watching and taking insights for further development of the design.
    If you would like to participate, please use this link to book a meeting. We will sent the link to the clickable prototype at the meeting.
  • Our UX team believes in the in the power of direct feedback and would like to invite you to participate in interviews, tests, and surveys.
    To stay in the loop and never miss an opportunity to share your thoughts, please subscribe to our UX research program. If you were previously part of the Plesk UX research program, please re-subscribe to continue receiving our invitations.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Question Suspicious visits to the website

Piekielko

Basic Pleskian
Server operating system version
Ubuntu 18.04.6 LTS
Plesk version and microupdate number
18.0.48
How is it that someone accessed my website using their own independent domain? This is the second time I found a similar problem in the logs. Earlier, I noticed the ca4mps.cf domain. What could be wrong?

Access Apache logs:
79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"
66.249.66.69 - - [30/Nov/2022:12:52:26 +0100] "GET /etniczne/bizuteria/przedbajkalscy-buraci HTTP/1.0" 200 18286 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +What Is Googlebot | Google Search Central | Documentation | Google Developers)"
103.225.200.236 - - [30/Nov/2022:12:52:26 +0100] "GET /kontakt HTTP/1.0" 200 19386 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
 

Attachments

  • screen.png
    screen.png
    38.6 KB · Views: 6
I think you are misinterpreting the log. The URL highlighted in bold in the log entry below indicates a Referer. I.e "The address from which a resource has been requested". So your websites hasn't been accessed via this URL, but rather has been requested from this URL.

79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"

More info on apache log formatting that might be useful to understand the log content: How to View & Analyze Apache Access & Error Log Files - Sematext

I am not familiar with Joomla, so I have no idea how it got in your sites cache. Seems a bit strange to me, but I am not sure.
 
Yes, you are right. I guess I was a little too nervous. But all the time I am surprised how this domain was saved in the cache as the displayed home page??. :-/
 
Back
Top