๐ฉ๐ช
dayda.net
2024-12-04 13:44:21
(1 year ago)
option=com_biblestudy&id=1&view=studieslist&controller=../../../../../../../../etc/passwd
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-11-26 23:24:25
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:23:49.539834 2024] [security2:error] [pid 14716:tid 14968] [client 161.123.152.76:33651] [client 161.123.152.76] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_kp&controller=../../../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/index.php"] [unique_id "Z0ZYhQhXN1-tm_FGp0dckQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Alejandro Docasar
2024-11-26 15:09:16
(1 year ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 00:43:07
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 20:42:59.150585 2024] [security2:error] [pid 25470:tid 25470] [client 161.123.152.76:53401] [client 161.123.152.76] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "80"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.stdavids-media.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stdavids-media.com"] [uri "/"] [unique_id "ZtetE6Jpp6fdqudgn5X_-gAAAAU"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:52:12
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:51:11.102156 2024] [security2:error] [pid 3087666:tid 3087690] [client 161.123.152.76:45071] [client 161.123.152.76] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /webadmin/reporter/view_server_log.php?act=stats&filename=log&offset=1&count=1&sortorder=0&filter=0&log=../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/webadmin/reporter/view_server_log.php"] [unique_id "ZtPIjzmHwNC8sxsTJsCElQAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 19:25:39
(2 years ago)
SS1: Web Attack GET /wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_ms ...
show more
SS1: Web Attack GET /wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php?page=%22%2F%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3Cb
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2024-06-27 12:50:04
(2 years ago)
| A web attack returned code 200 (success).
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-27 06:51:26
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 161.123.152.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 02:50:02.533506 2024] [security2:error] [pid 31307:tid 47876656875264] [client 161.123.152.76:33865] [client 161.123.152.76] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||mail.kettlehill.net|F|2"] [data "Matched Data: <script found within REQUEST_URI: /squid.svg?title=notfound&text=thisisnotthepageyouarelookingfor!&background=\\x22><script>alert(document.domain)</script><imgsrc=\\x22&small"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.kettlehill.net"] [uri "/squid.svg"] [unique_id "Zn0LmmKXMmBmzEOxohekCwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
prod.lkwd.net
2024-02-28 08:09:00
(2 years ago)
On 26 February there were several attempts from this IP address to exploit our backend services to f ...
show more
On 26 February there were several attempts from this IP address to exploit our backend services to fraudulently acquire paid for items
show less
Fraud Orders
Bad Web Bot
Web App Attack
๐บ๐ธ
ChamberofCommerce.com
2023-11-06 00:46:55
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐บ๐ธ
ChamberofCommerce.com
2023-11-02 04:21:57
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐บ๐ธ
ChamberofCommerce.com
2023-10-30 22:11:21
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot