๐ธ๐ช
Per-Erik Runebert
2024-08-29 08:39:05
(2 years ago)
Excessive unauthorized requests
Hacking
Anonymous
2024-08-28 04:30:03
(2 years ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-28 00:41:41
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.co ...
show more
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 27 20:41:34.661285 2024] [security2:error] [pid 10443:tid 10443] [client 18.237.103.207:53885] [client 18.237.103.207] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||cs-mall.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /category.php?cat=<script>alert('xss')</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "cs-mall.com"] [uri "/category.php"] [unique_id "Zs5yPnZ9jYzFH1bAAdFCmQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TheMadBeaker
2024-08-27 23:55:40
(2 years ago)
Fail2Ban Ban Triggered
HTTP Bot Harvester Detected
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-27 23:45:21
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.co ...
show more
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 27 19:45:14.391157 2024] [security2:error] [pid 13467:tid 13467] [client 18.237.103.207:50621] [client 18.237.103.207] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||gestionimmobiliereadstock.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /script/preview.php?action=<script>alert('xss')</script>&controller=pjlistings&id=89"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "gestionimmobiliereadstock.com"] [uri "/script/preview.php"] [unique_id "Zs5lClmFUJ1nHnTmae8_hwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2024-08-27 22:54:01
(2 years ago)
(mod_security) mod_security triggered on hostname [redacted] 18.237.103.207 (US/United States/ec2-18 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 18.237.103.207 (US/United States/ec2-18-237-103-207.us-west-2.compute.amazonaws.com)
show less
SQL Injection
๐ซ๐ท
Sklurk
2024-08-27 22:45:07
(2 years ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-27 22:23:33
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.co ...
show more
(mod_security) mod_security (id:212620) triggered by 18.237.103.207 (ec2-18-237-103-207.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 27 18:23:30.212799 2024] [security2:error] [pid 3136:tid 3136] [client 18.237.103.207:61480] [client 18.237.103.207] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.oualierealty.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /index.php?action=<script>alert('xss')</script>&id=589"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "Zs5R4unovwTln9Qg3Tub5gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RidgeStar
2024-08-27 21:30:35
(2 years ago)
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
2024-08-27T14:30:35-0 ...
show more
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
2024-08-27T14:30:35-07:00: <script>alert('XSS')</script>
show less
Port Scan
Hacking
๐ถ๐ฆ
CB Infosec
2024-03-04 05:41:00
(2 years ago)
Illegal URL 185 49.333%
Illegal request length,Illegal URL length,Illegal URL,Illegal file type 73 ...
show more
Illegal URL 185 49.333%
Illegal request length,Illegal URL length,Illegal URL,Illegal file type 73 19.467%
N/A 40 10.667%
Illegal parameter,Illegal URL 35 9.333%
Illegal query string length,Illegal request length,Illegal URL length,Illegal parameter,Illegal URL,Illegal file type 11 2.933%
Illegal URL length,Illegal URL 7 1.867%
Illegal URL length,Illegal parameter,Illegal URL 4 1.067%
Illegal request length,Illegal URL length,Illegal POST data length,Illegal parameter,Illegal URL,Illegal file type 4 1.067%
Evasion technique detected,Illegal URL 3 0.8%
HTTP protocol compliance failed,Illegal method
show less
Web App Attack