|
π«π·
bigorre.org
|
|
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
|
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 23:43:35.613013 2026] [security2:error] [pid 31560:tid 31560] [client 166.88.64.106:47729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.production"] [unique_id "aWsTd7hvZdRqoVTSdRMTfQAAAB4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211190) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:211190) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:14:58.608902 2025] [security2:error] [pid 31734:tid 31761] [client 166.88.64.106:40177] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /components/com_moofaq/includes/file_includer.php?gzip=0&file=/../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.kettlehill.com"] [uri "/components/com_moofaq/includes/file_includer.php"] [unique_id "aVLTMmCDVM70TD0LIjvX_AAAAVQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211070) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:211070) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 05:31:38.690264 2025] [security2:error] [pid 3335:tid 3360] [client 166.88.64.106:47911] ModSecurity: Access denied with code 403 (phase 1). Pattern match "," at REQUEST_HEADERS:Transfer-Encoding. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "38"] [id "211070"] [rev "1"] [msg "COMODO WAF: HTTP Request Smuggling Attack.||kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/tmui/login.jsp"] [unique_id "aSrLiity0hTJmdQbFg41MwAAAhA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210730) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:06:56.614440 2025] [security2:error] [pid 14787:tid 14787] [client 166.88.64.106:48221] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/1.sql"] [unique_id "aRWtwI0uAA7zE3BPVzyaKwAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
dayda.net
|
|
query: action=dzsap_download&link=../../../../../../../../../../../../../etc/passwd
|
Bad Web Bot
|
|
|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:23:52.675057 2025] [security2:error] [pid 291259:tid 291329] [client 166.88.64.106:55337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/.git/config"] [unique_id "aIVxmGQX5AgegSXcd9rSbQAAARg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240950) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:240950) triggered by 166.88.64.106 (166-88-64-106.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 16:53:59.687881 2025] [security2:error] [pid 3491492:tid 3491492] [client 166.88.64.106:43479] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcalendars.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcalendars.farmers123.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "aDjJZ8dXEX3JruQedLRpQgAAABE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| A web attack returned code 200 (success).
|
Hacking
SQL Injection
Web App Attack
|
|