• Hi, Pleskians! We are running a UX testing of our upcoming product intended for server management and monitoring.
    We would like to invite you to have a call with us and have some fun checking our prototype. The agenda is pretty simple - we bring new design and some scenarios that you need to walk through and succeed. We will be watching and taking insights for further development of the design.
    If you would like to participate, please use this link to book a meeting. We will sent the link to the clickable prototype at the meeting.
  • Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Question Suspicious visits to the website

Piekielko

Basic Pleskian
Server operating system version
Ubuntu 18.04.6 LTS
Plesk version and microupdate number
18.0.48
How is it that someone accessed my website using their own independent domain? This is the second time I found a similar problem in the logs. Earlier, I noticed the ca4mps.cf domain. What could be wrong?

Access Apache logs:
79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"
66.249.66.69 - - [30/Nov/2022:12:52:26 +0100] "GET /etniczne/bizuteria/przedbajkalscy-buraci HTTP/1.0" 200 18286 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +What Is Googlebot | Google Search Central | Documentation | Google Developers)"
103.225.200.236 - - [30/Nov/2022:12:52:26 +0100] "GET /kontakt HTTP/1.0" 200 19386 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
 

Attachments

  • screen.png
    screen.png
    38.6 KB · Views: 6
I think you are misinterpreting the log. The URL highlighted in bold in the log entry below indicates a Referer. I.e "The address from which a resource has been requested". So your websites hasn't been accessed via this URL, but rather has been requested from this URL.

79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"

More info on apache log formatting that might be useful to understand the log content: How to View & Analyze Apache Access & Error Log Files - Sematext

I am not familiar with Joomla, so I have no idea how it got in your sites cache. Seems a bit strange to me, but I am not sure.
 
Yes, you are right. I guess I was a little too nervous. But all the time I am surprised how this domain was saved in the cache as the displayed home page??. :-/
 
Back
Top