(mod_security) mod_security (id:211820) triggered by 146.103.3.214 (-): 1 in the last 300 secs; Port ...
show more(mod_security) mod_security (id:211820) triggered by 146.103.3.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:30:19.134782 2025] [security2:error] [pid 26213:tid 26646] [client 146.103.3.214:45307] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:; ?(?:(?:(?:trunc|cre|upd)at|renam)e|(?:inser|selec)t|de(?:lete|sc)|alter|load) ?[\\\\[(]?\\\\b\\\\w{2,}|\\\\bcreate function .+ returns\\\\b))" at ARGS:rfilter. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "63"] [id "211820"] [rev "4"] [msg "COMODO WAF: Detects MySQL UDF injection and other data/structure manipulation attempts||www.kettlehill.com|F|2"] [data "Matched Data: ;SELECT SLEEP found within ARGS:rfilter: \\x22or \\x22\\x22=\\x22((\\x22));SELECT SLEEP(10);"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.kettlehill.com"] [uri "/graph_view.php"] [unique_id "aVLIu0pty-jo8UW-4yKUJQAAAY8"]
show less