๐ฎ๐ฉ
hermawan
2025-07-11 18:19:41
(11 months ago)
[Sat Jul 12 01:19:16.275179 2025] [security2:error] [pid 144085:tid 140300039206592] [client 162.253 ...
show more
[Sat Jul 12 01:19:16.275179 2025] [security2:error] [pid 144085:tid 140300039206592] [client 162.253.155.145:33618] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 162.253.155.145 request_line = GET / HTTP/1.1 Request URI RAW = / Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aHFVpCcj2DO_SUpMkj8xbgAAAM4"], referer http://karangploso.jatim.bmkg.go.id [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[144126] [T94JWevpK7o] [aHFVpCcj2DO_SUpMkj8xbgAAAM4] keep_alive=[0] [2025-07-12 01:19:16.275183] [R:aHFVpCcj2DO_SUpMkj8xbgAAAM4] UA:'Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-11 16:18:26
(11 months ago)
Linksys RE6500 Remote Command Injection Vulnerability(90276)
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-07-11 10:13:21
(11 months ago)
WP Admin Scan Activities
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-11 07:15:03
(11 months ago)
[Fri Jul 11 14:13:48.080759 2025] [security2:error] [pid 50145:tid 140129263933120] [client 162.253. ...
show more
[Fri Jul 11 14:13:48.080759 2025] [security2:error] [pid 50145:tid 140129263933120] [client 162.253.155.145:11218] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 162.253.155.145 request_line = GET / HTTP/1.1 Request URI RAW = / Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aHC5rA77ts7UiwR1MoJnBwAAAAM"], referer http://karangploso.jatim.bmkg.go.id [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[50178] [6dUhDSJ6kc0] [aHC5rA77ts7UiwR1MoJnBwAAAAM] keep_alive=[0] [2025-07-11 14:13:48.080769] [R:aHC5rA77ts7UiwR1MoJnBwAAAAM] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 17:57:16
(11 months ago)
HP Universal CMDB Server Credential Code Execution Vulnerability(39273)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 17:34:59
(11 months ago)
Suspicious File Downloading Detection(54469)
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-09 17:18:27
(11 months ago)
[Thu Jul 10 00:18:27.452102 2025] [security2:error] [pid 13996:tid 140404980684480] [client 162.253. ...
show more
[Thu Jul 10 00:18:27.452102 2025] [security2:error] [pid 13996:tid 140404980684480] [client 162.253.155.145:36326] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "371"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 162.253.155.145 request_line = GET / HTTP/1.1 Request URI RAW = / Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aG6kY_-atJ1ETw1snv0P1gAAAA4"], referer http://karangploso.jatim.bmkg.go.id [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[14037] [aHzeQ8JA7yA] [aG6kY_-atJ1ETw1snv0P1gAAAA4] keep_alive=[0] [2025-07-10 00:18:27.452108] [R:aG6kY_-atJ1ETw1snv0P1gAAAA4] UA:'Mozilla/5.0 (Windows NT 6.2; rv:128.9) Gecko/20100101 Firefox
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 17:12:29
(11 months ago)
Ruijieyi Networks Remote Command Execution Vulnerability(90818)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 16:55:41
(11 months ago)
Eyou Email System Remote Command Execution Vulnerability(91329)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 16:40:17
(11 months ago)
Adobe ColdFusion CKeditor Unrestricted File Upload Vulnerability(38319)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 16:18:19
(11 months ago)
phpunit Remote Code Execution Vulnerability(55852)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-09 15:40:37
(11 months ago)
PHPUnit.Eval-stdin.PHP.Remote.Code.Execution
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-07-09 15:12:28
(11 months ago)
WP Admin Scan Activities
Web App Attack
๐ฎ๐ฉ
Burayot
2025-07-09 04:30:51
(11 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 162.253.155.145 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 162.253.155.145 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐จ๐ญ
backslash
2025-07-01 03:30:10
(11 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot