• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question what do you do for this type of thing... (security?)

larryk

Regular Pleskian
Code:
2017-01-16 04:15:00    Access    89.133.235.113    301    POST /xmlrpc.php HTTP/1.1        Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1    178    nginx access

Code:
2017-01-16 04:15:01    Error    89.133.235.113    405    GET /xmlrpc.php HTTP/1.1        Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1    53    nginx access

as you can see, those entries are 1 second apart. And really, that is just an example of the entries I see...
I know those are just bots, spammers, hackers, etc. looking for holes or exploits on my sites, etc. etc.


My plesk Onyx server:
OS ‪CentOS Linux 7.2.1511 (Core)‬
Product Plesk Onyx
Version 17.0.17 Update #12, last updated on Jan 13, 2017 12:24 PM

I have WAF with atomic rules updated daily, but trying to install ASL (so far, can't get ASL installed, but trying)

anyway, what do you do when you see 100s or 1000s of entries similar to the above?

a) nothing --- as they are not getting in and can't be prevented/stopped
b) hoping they don't get in
c) most are ignored, but some extreme cases the IP is blocked
d) XYZ software is installed and my plesk is secure enough
e) ABC is done to block, prevent, or stop problems

I'm hoping, but don't know until installed, that ASL will give me the tools and a way to deal with these type of issues, MUCH more easily than I do now. That is my goal.


QUESTION -- when these entries or accesses to my vhost domains occur... (say many across multiple domains)... does that effect server performance?

thoughts on what you do for stuff like this?

thanks!
 
Back
Top