πΊπΈ
TPI-Abuse
2025-08-05 19:06:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 15:06:21.544512 2025] [security2:error] [pid 25330:tid 25330] [client 104.239.13.23:36229] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nbcnewsradio.com"] [uri "/MyErrors.log"] [unique_id "aJJWLaqaX4Y2VMGuTRYeywAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-24 22:25:16
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-07-01 05:52:57
(11 months ago)
(mod_security) mod_security (id:212340) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212340) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 01:52:51.630744 2025] [security2:error] [pid 15244:tid 15346] [client 104.239.13.23:40207] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "-->" at ARGS:mapid. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "56"] [id "212340"] [rev "5"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||kettlehill.com|F|2"] [data "Matched Data: --> found within ARGS:mapid: --><img src onerror=alert(document.domain)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kettlehill.com"] [uri "/"] [unique_id "aGN3s6Itqwp4Tiul4V7oWgAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-05 18:00:02
(1 year ago)
| PHP CGI-bin vulnerability attempt.
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-01 02:57:39
(1 year ago)
(mod_security) mod_security (id:220150) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:220150) triggered by 104.239.13.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 22:53:38.629658 2025] [security2:error] [pid 10928:tid 11080] [client 104.239.13.23:44979] [client 104.239.13.23] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:bwg_tag_id_bwg_thumbnails_0[]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||kettlehill.com|F|2"] [data ")\\x22unionselect1,2,3,4,5,6,7,concat(md5(999999999),0x2c,8),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--g"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aBLiMmhpHha-h36oCB5izgAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2023-11-09 11:23:30
(2 years ago)
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 104.239.13.23 (C ...
show more
(apache-bow-document) Failed apache-bow-scanners trigger with match [redacted] from 104.239.13.23 (CA/Canada/-)
show less
Hacking