Forum Moderators: phranque

Message Too Old, No Replies

Is this indicative of a security risk?

         

beavis

2:17 pm on Mar 7, 2007 (gmt 0)

10+ Year Member



I am at a shared web host and was looking through my logs this morning and I have found that recently the highest number of page views and highest bandwidth usage have come from a Brazilian host:

focuslinux.sexuallyorienteddomainname.com.br

When I enter the above (with actual domain) into my browser, it leads to a porn site.

I don't fully understand what is going on here. Typically, the hosts are comcast, roadrunner, etc... ie. the user's ISP. Why are these porn sites coming up as "hosts" and is this likely some sort of security risk? For a while someone was abusing my online form to send spam e-mail, but I think I stopped that.

mcavic

3:54 pm on Mar 7, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Most viruses and spam that I see come from dynamic ISP addresses, just like real users. When I see a static name like that, it tends to make me think it's someone visiting for a specific purpose, like a bot.

But it is interesting that they are the largest user. I'd check what pages they're visiting. Are they hitting the same pages over and over, posting forms and failing your spam check, etc.

It could be an anonymous proxy service, but it would have to be pretty popular to be your largest user.

SteveWh

12:57 am on Mar 8, 2007 (gmt 0)

10+ Year Member



It could simply be a site trying to become your top ranked visitor. Some sites publish their site statistics. In those cases, the published statistics, with them at the top, become a useful linkback to their site, to increase traffic and page rank.

But to your specific question about security risk, no it isn't any particular indication of a security problem. I generally don't block IP addresses or get concerned unless I see them do something that is obviously of malicious intent, and even then, if your site is basically secure, the attempts will fail, anyway. The fact that someone tries to hack you doesn't mean they'll succeed. The real measure of site security is whether you are aware of security best practices and follow them. If you do, there's not a lot to worry about.

[edited by: SteveWh at 1:04 am (utc) on Mar. 8, 2007]

beavis

2:09 pm on Mar 8, 2007 (gmt 0)

10+ Year Member



Unfortunately, I don't think I have a way to see what pages are being viewed from this host. My stats program does not provide such a statistic and I e-mailed my hosting company and they don't either.

I don't know much about raw log files, but I assume the information would be in there somewhere, though I don't know how to extract it.