๐บ๐ธ
TPI-Abuse
2024-09-03 18:39:53
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:39:13.562547 2024] [security2:error] [pid 9131:tid 9131] [client 104.232.211.240:54287] [client 104.232.211.240] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /maint/modules/home/index.php?lang=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00english"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stdavids-media.com"] [uri "/maint/modules/home/index.php"] [unique_id "ZtdX0Vf9wjcel4c7XJuHTAAAAAA"], referer: mail.stdavids-media.com/maint/index.php?packages
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:56:49
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240950) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:56:29.823075 2024] [security2:error] [pid 3087536:tid 3087543] [client 104.232.211.240:42555] [client 104.232.211.240] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcalendars.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcalendars.kettlehill.net"] [uri "/_users/org.couchdb.user:poc"] [unique_id "ZtPJzUkxOUU9miRPzMMetAAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-23 05:07:05
(1 year ago)
104.232.211.240 - - [23/Aug/2024:07:07:04 +0200] "GET /..../..../..../..../..../..../..../..../..../ ...
show more
104.232.211.240 - - [23/Aug/2024:07:07:04 +0200] "GET /..../..../..../..../..../..../..../..../..../windows/win.ini HTTP/1.1" 403 5370 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 4743
...
show less
Hacking
๐ฉ๐ช
ps-center
2024-07-15 18:05:09
(1 year ago)
SS1: Web Attack GET /phpmyadmin/setup/index.php?page=servers&mode=test&id=%22%3e%3C%2Fscript%3E%3Csc ...
show more
SS1: Web Attack GET /phpmyadmin/setup/index.php?page=servers&mode=test&id=%22%3e%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2024-07-11 17:25:03
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-27 07:12:58
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 03:12:53.813355 2024] [security2:error] [pid 31347:tid 47386280683264] [client 104.232.211.240:48781] [client 104.232.211.240] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_cmimarketplace&Itemid=70&viewit=/../../../../../../etc/passwd&cid=1"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.kettlehill.com"] [uri "/index.php"] [unique_id "Zn0Q9YVrTcN0CWUgIqHunAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:11:57
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-01 16:06:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.232.211.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 01 12:05:37.479260 2024] [security2:error] [pid 12508:tid 47912206345984] [client 104.232.211.240:57805] [client 104.232.211.240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/kettlehill.com.db"] [unique_id "ZgrbUVzC3Qy70orr9wrfgQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:54:19
(2 years ago)
WP scan
Web App Attack