Forum Moderators: phranque
focuslinux.sexuallyorienteddomainname.com.br
When I enter the above (with actual domain) into my browser, it leads to a porn site.
I don't fully understand what is going on here. Typically, the hosts are comcast, roadrunner, etc... ie. the user's ISP. Why are these porn sites coming up as "hosts" and is this likely some sort of security risk? For a while someone was abusing my online form to send spam e-mail, but I think I stopped that.
But it is interesting that they are the largest user. I'd check what pages they're visiting. Are they hitting the same pages over and over, posting forms and failing your spam check, etc.
It could be an anonymous proxy service, but it would have to be pretty popular to be your largest user.
But to your specific question about security risk, no it isn't any particular indication of a security problem. I generally don't block IP addresses or get concerned unless I see them do something that is obviously of malicious intent, and even then, if your site is basically secure, the attempts will fail, anyway. The fact that someone tries to hack you doesn't mean they'll succeed. The real measure of site security is whether you are aware of security best practices and follow them. If you do, there's not a lot to worry about.
[edited by: SteveWh at 1:04 am (utc) on Mar. 8, 2007]
I don't know much about raw log files, but I assume the information would be in there somewhere, though I don't know how to extract it.