|
π©πͺ
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities - 13
|
Exploited Host
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 13:38:49.836345 2024] [security2:error] [pid 3173980:tid 3173980] [client 13.229.203.40:46032] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|www.frelsburg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.frelsburg.com"] [uri "/xmlrpc.php"] [unique_id "ZrZUKZsTOz4iQPoK5HZS5gAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π§πͺ
cmbplf
|
|
503 requests to */xmlrpc.php
|
Brute-Force
Bad Web Bot
|
|
|
π©πͺ
SpaceHost-Server
|
|
13.229.203.40 - - [09/Aug/2024:12:27:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 1112 "-" "Mozilla/5.0 ...
show more
13.229.203.40 - - [09/Aug/2024:12:27:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 1112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
13.229.203.40 - - [09/Aug/2024:12:27:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 1112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
13.229.203.40 - - [09/Aug/2024:12:27:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 1112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
π²πΉ
Malta
|
|
13.229.203.40 - - [09/Aug/2024:07:51:13 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; ...
show more
13.229.203.40 - - [09/Aug/2024:07:51:13 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36"
Brute-force password attempt
show less
|
Hacking
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 01:36:27.895221 2024] [security2:error] [pid 3057515:tid 3057538] [client 13.229.203.40:34382] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 128.127.104.80 (1+1 hits since last alert)|www.rpiusa.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.rpiusa.net"] [uri "/xmlrpc.php"] [unique_id "ZrWq2wgreg0T5Cn1ciUXcgAAAVA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 22:49:24.427907 2024] [security2:error] [pid 2857:tid 2857] [client 13.229.203.40:34974] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|didactrend.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "didactrend.com"] [uri "/xmlrpc.php"] [unique_id "ZrWDtKR01xYCdaH1oxStSAAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 20:41:27.272996 2024] [security2:error] [pid 17143:tid 17143] [client 13.229.203.40:37430] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|www.communiongatherings.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.communiongatherings.com"] [uri "/xmlrpc.php"] [unique_id "ZrVltw31GEGJ56MQqsSB_wAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 10:13:28.168228 2024] [security2:error] [pid 15958:tid 15958] [client 13.229.203.40:57732] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|www.samemahama2024.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.samemahama2024.com"] [uri "/xmlrpc.php"] [unique_id "ZrTSiIth8u1BSi3oF5bP6QAAABw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 06:09:27.120291 2024] [security2:error] [pid 2012:tid 2012] [client 13.229.203.40:49808] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|www.dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dianamead.com"] [uri "/xmlrpc.php"] [unique_id "ZrSZVx2a0SbKRWAu86J7bAAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1 ...
show more
(mod_security) mod_security (id:240335) triggered by 13.229.203.40 (ec2-13-229-203-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 02:39:23.225831 2024] [security2:error] [pid 26069:tid 26069] [client 13.229.203.40:47794] [client 13.229.203.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.229.203.40 (+1 hits since last alert)|www.aeongames.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.aeongames.com"] [uri "/xmlrpc.php"] [unique_id "ZrRoG8wGBLUz5svX-c6uvAAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|