I'm not sure what's happening but i've just found, that someone has registered domain name *-auth.ga
that displays my website. I'm not sure how can i block that kind of issue, i don't just want to ban each domain directly. I'm looking for a more general solution.
This website is not using iframe, my nginx host has a domain name specified (dns of that fake domain is not pointing to my server so it's not an issue actually i think), i'm also forcing SSL connection but this fake domain uses ssl as well (https://*-auth.ga
) so this all seems really misterious. Anyway, even with the basic protection settings mentioned above, i'm still able to reach my website under fake domain and i can see the access logs on my server (so it's not any kind of a mirror nor anything like that)
How can i prevent such behaviour in nginx/app? can anyone explain me what's that, why someone is doing it and why/if it can be dangerous in any way? I'm not even sure how to google for that nor what tags to use in here. Thanks in advance!
Comments
Post a Comment