• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question Suspicious visits to the website

Piekielko

Basic Pleskian
Server operating system version
Ubuntu 18.04.6 LTS
Plesk version and microupdate number
18.0.48
How is it that someone accessed my website using their own independent domain? This is the second time I found a similar problem in the logs. Earlier, I noticed the ca4mps.cf domain. What could be wrong?

Access Apache logs:
79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"
66.249.66.69 - - [30/Nov/2022:12:52:26 +0100] "GET /etniczne/bizuteria/przedbajkalscy-buraci HTTP/1.0" 200 18286 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +What Is Googlebot | Google Search Central | Documentation | Google Developers)"
103.225.200.236 - - [30/Nov/2022:12:52:26 +0100] "GET /kontakt HTTP/1.0" 200 19386 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
 

Attachments

  • screen.png
    screen.png
    38.6 KB · Views: 6
I think you are misinterpreting the log. The URL highlighted in bold in the log entry below indicates a Referer. I.e "The address from which a resource has been requested". So your websites hasn't been accessed via this URL, but rather has been requested from this URL.

79.142.79.87 - - [30/Nov/2022:12:52:08 +0100] "GET / HTTP/1.0" 200 115313 "https:// m.meendoru.net /" "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0"

More info on apache log formatting that might be useful to understand the log content: How to View & Analyze Apache Access & Error Log Files - Sematext

I am not familiar with Joomla, so I have no idea how it got in your sites cache. Seems a bit strange to me, but I am not sure.
 
Yes, you are right. I guess I was a little too nervous. But all the time I am surprised how this domain was saved in the cache as the displayed home page??. :-/
 
Back
Top