|
๐บ๐ธ
Brian
|
|
ModSecurity: Warning. detected SQLi using libinjection with fingerprint
|
SQL Injection
|
|
|
๐บ๐ธ
eacontent
|
|
2x eg 154.16.70.28 - - [20/Jan/2026:13:54:05 -0500] "GET /.env HTTP/1.1" 404 34 "-" "Mozilla/5.0 (Li ...
show more
2x eg 154.16.70.28 - - [20/Jan/2026:13:54:05 -0500] "GET /.env HTTP/1.1" 404 34 "-" "Mozilla/5.0 (Linux; Android 9; ASUS_I005DA Build/PI; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/133.0.6943.122 Mobile"
show less
|
Hacking
|
|
|
๐ซ๐ท
COMAITE
|
|
SQL injection attempt from 154.16.70.28.
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 20:45:31.349809 2026] [security2:error] [pid 970117:tid 970151] [client 154.16.70.28:38597] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||stonyp.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "stonyp.com"] [uri "/"] [unique_id "aXAvu2Z443ZIVd85PwDKIAAAAIQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
|
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 20 18:32:15.158315 2026] [security2:error] [pid 17030:tid 17030] [client 154.16.70.28:59287] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.cybersoftware.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cybersoftware.org"] [uri "/"] [unique_id "aXAQf2DRk8CwajCI-d0zCwAAACM"], referer: http://get.globalprime.com/afs/come.php?atype=1&atype=%27&brandid=3&cid=521&ctgid=1003
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ช๐ธ
el-brujo
|
|
Cloudflare WAF: Request Path: /.env Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 (Linux; Android 9; ASUS_I005DA Build/PI; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/133.0.6943.122 Mobile Action: block Source: firewallManaged ASN Description: TRAVCHIS Country: RO Method: GET Timestamp: 2026-01-20T18:31:52Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
|
Hacking
SQL Injection
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 154.16.70.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 20:34:24.509014 2026] [security2:error] [pid 24410:tid 24449] [client 154.16.70.28:49583] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.seips.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.seips.org"] [uri "/viewitem.php"] [unique_id "aW7boM9FNYdUmVz3W567rQAAAYQ"], referer: http://www.seips.org/viewitem.php?ID=+or+1%3D+AND+0%3DCAST%28COALESCE%28%28SELECT+version%28%29%29%3A%3Atext%2C+CHR%2832%29%29%3A%3Atext+%7C%7C+CHR%2867%29+AS+NUMERIC%29--+and+1%3D1
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Multiple SQL injection attempts from same source ip.(multiple servers)
|
Hacking
SQL Injection
Web App Attack
|
|
|
๐ฑ๐ป
garmtech.com
|
|
IM360 WAF: SQL Injection Attack: Common DB Names Detected
|
SQL Injection
|
|