๐ฉ๐ช
Alejandro Docasar
2024-11-28 12:00:26
(1 year ago)
Web App Attack
๐ฉ๐ช
ps-center
2024-11-27 08:05:28
(1 year ago)
SS1: Web Attack GET /admin/manage_user.php?id=-1%20union%20select%201,md5(999999999),3,4,5--+
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2024-11-22 03:38:49
(1 year ago)
fc=module&module=productcomments&controller=CommentGrade&id_products%5B%5D=1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-27 02:24:34
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240950) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 22:23:43.523103 2024] [security2:error] [pid 16198:tid 16316] [client 154.30.251.1:34173] [client 154.30.251.1] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpanel.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpanel.kettlehill.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "Zx2kL4dxfUWkKNYQaRAgUQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-14 05:22:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-03 18:33:48
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:33:40.129820 2024] [security2:error] [pid 19357:tid 19357] [client 154.30.251.1:33135] [client 154.30.251.1] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "80"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcontacts.stdavids-media.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stdavids-media.com"] [uri "/debug.cgi"] [unique_id "ZtdWhBfB_t7Eb3PL87GNmgAAAAk"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-27 20:22:15
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 16:22:08.903708 2024] [security2:error] [pid 22440:tid 22476] [client 154.30.251.1:46057] [client 154.30.251.1] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.kettlehill.net|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?author=1</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.kettlehill.net"] [uri "/"] [unique_id "ZqVW8BUtUDUbeeZ7GhUV4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 18:05:14
(1 year ago)
SS1: Web Attack POST /wp-admin/admin-ajax.php?td_theme_name=Newspaper&v=11.2
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2024-07-13 22:39:10
(1 year ago)
query: ../../../../../../../../etc/passwd
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2024-06-29 02:08:23
(1 year ago)
Suspicious activity detected by Modsecurity [Suspicious IP found on 5 endpoints 19 hits. Reincident ...
show more
Suspicious activity detected by Modsecurity [Suspicious IP found on 5 endpoints 19 hits. Reincident by 1. Rules:]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-15 01:51:51
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 154.30.251.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 14 21:51:45.605038 2024] [security2:error] [pid 20072:tid 47952258868992] [client 154.30.251.1:57575] [client 154.30.251.1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.staging.kettlehill.com"] [uri "/.env"] [unique_id "ZkQVMZM3wD4Fbah2IMww2gAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:24:46
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:50:03
(2 years ago)
WP scan
Web App Attack