๐ฎ๐ฉ
hermawan
2023-12-17 04:47:46
(2 years ago)
[Sun Dec 17 11:47:44.809989 2023] [security2:error] [pid 16755:tid 140281869489728] [client 185.185. ...
show more
[Sun Dec 17 11:47:44.809989 2023] [security2:error] [pid 16755:tid 140281869489728] [client 185.185.83.118:53711] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Client" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "6"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Client found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /admin/js/filemanager/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/admin/js/filemanager/filemanager/dialog.php"] [unique_id "ZX59cNoA1pHKuGcXey_T_AAAAdY"], referer https://karangploso.jatim.bmkg.go.id/admin/js/filemanager/filemanager/dialog.php [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[16912] [x52PVS1wePo] [ZX59cNoA1pHKuGcXey_T_AAAAdY] keep_alive=[0] [2023-12-17 11:47:44.809993] [R:ZX59cNoA1pHKuGcXey_T_AAAAdY] UA:'Go-http
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2023-12-16 05:19:45
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-16 04:49:05
(2 years ago)
[Sat Dec 16 11:49:03.740680 2023] [security2:error] [pid 131421:tid 140561151403584] [client 185.185 ...
show more
[Sat Dec 16 11:49:03.740680 2023] [security2:error] [pid 131421:tid 140561151403584] [client 185.185.83.118:59158] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Client" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "6"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Client found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /asset/tinymce/plugins/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/asset/tinymce/plugins/filemanager/dialog.php"] [unique_id "ZX0sP5Jd7IJVQuy_N4ahPAAAAqE"], referer https://karangploso.jatim.bmkg.go.id/asset/tinymce/plugins/filemanager/dialog.php [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[131581] [s7hsPPExHtU] [ZX0sP5Jd7IJVQuy_N4ahPAAAAqE] keep_alive=[0] [2023-12-16 11:49:03.740683] [R:ZX0sP5Jd7IJVQuy_N4ahPAAAAqE] UA:'Go
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-05 10:49:29
(2 years ago)
[Tue Dec 05 17:49:27.463244 2023] [security2:error] [pid 7158:tid 140564414592576] [client 185.185.8 ...
show more
[Tue Dec 05 17:49:27.463244 2023] [security2:error] [pid 7158:tid 140564414592576] [client 185.185.83.118:58550] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 1). Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1881"] [id "920300"] [msg "Request Missing an Accept Header"] [data "Matched Data: gzip found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /plugins/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/plugins/filemanager/dialog.php"] [unique_id "ZW8ANz55FtMhlDdxCTdoaAAAANU"], referer https://karangploso.jatim.bmkg.go.id/plugins/filemanager/dialog.php
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2023-12-05 09:24:51
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-05 09:07:36
(2 years ago)
[Tue Dec 05 16:07:30.401884 2023] [security2:error] [pid 516643:tid 139653319476800] [client 185.185 ...
show more
[Tue Dec 05 16:07:30.401884 2023] [security2:error] [pid 516643:tid 139653319476800] [client 185.185.83.118:51529] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 1). Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1881"] [id "920300"] [msg "Request Missing an Accept Header"] [data "Matched Data: gzip found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/filemanager/dialog.php"] [unique_id "ZW7oUku7ObxnTO7_PCSZ8gAAAPk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[516780] [qghzkP8yKpI] [ZW7oUku7
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-11-07 14:31:43
(2 years ago)
[Tue Nov 07 21:31:41.656014 2023] [security2:error] [pid 12907:tid 139682704766528] [client 185.185. ...
show more
[Tue Nov 07 21:31:41.656014 2023] [security2:error] [pid 12907:tid 139682704766528] [client 185.185.83.118:50167] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 2). Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1690"] [id "920300"] [msg "Request Missing an Accept Header"] [data "Matched Data: accept-encoding found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /public/plugins/tinymce/js/tinymce/plugins/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/public/plugins/tinymce/js/tinymce/plugins/filemanager/dialog.php"] [unique_id "ZUpKTdQlTOZ0WPtneWrDQQAAAg
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-11-07 13:26:33
(2 years ago)
[Tue Nov 07 20:26:29.794956 2023] [security2:error] [pid 475712:tid 140609092310592] [client 185.185 ...
show more
[Tue Nov 07 20:26:29.794956 2023] [security2:error] [pid 475712:tid 140609092310592] [client 185.185.83.118:51703] [client 185.185.83.118] ModSecurity: Access denied with code 403 (phase 2). Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1690"] [id "920300"] [msg "Request Missing an Accept Header"] [data "Matched Data: accept-encoding found within REQUEST_HEADERS:User-Agent: Go-http-client/1.1 request_line = GET /filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/filemanager/dialog.php"] [unique_id "ZUo7BWgLXFu_JOllps9F5QAAA8A"], referer https://karangploso.jatim.bmkg.go.id/filemanager/dialog.php [staklim-j
...
show less
Hacking
Web App Attack
๐ฉ๐ช
niceshops.com
2023-11-06 08:10:42
(2 years ago)
Web Attack ([06/Nov/2023:09:09:36.842] GET /admin/filemanager/dialog.php)
Web App Attack
๐จ๐ฟ
antihack.anarchista.xyz
2023-11-03 14:00:37
(2 years ago)
"Failed password for invalid user ssh2,hack script-phyton"
Brute-Force
SSH
๐ฉ๐ช
AMRE
2023-10-30 15:01:50
(2 years ago)
Probing PHP framework vulnerabilities
Brute-Force
๐ฉ๐ช
Lacrimosa99
2023-10-30 08:12:53
(2 years ago)
185.185.83.118 - - [30/Oct/2023:07:28:53 +0100] "GET /filemanager/dialog.php HTTP/1.1" 404 5277 "htt ...
show more
185.185.83.118 - - [30/Oct/2023:07:28:53 +0100] "GET /filemanager/dialog.php HTTP/1.1" 404 5277 "http://devil-hunter-multigaming.de/filemanager/dialog.php" "Go-http-client/1.1"
185.185.83.118 - - [30/Oct/2023:07:28:53 +0100] "GET /filemanager/dialog.php HTTP/1.1" 404 5277 "http://devil-hunter-clan.de/filemanager/dialog.php" "Go-http-client/1.1"
185.185.83.118 - - [30/Oct/2023:09:12:53 +0100] "GET /admin/filemanager/dialog.php HTTP/1.1" 404 5277 "http://devil-hunter-multigaming.de/admin/filemanager/dialog.php" "Go-http-client/1.1"
...
show less
Web Spam
๐ฉ๐ช
Hiffo
2023-10-30 06:22:51
(2 years ago)
derorga.de:443 185.185.83.118 - - [30/Oct/2023:07:22:51 +0100] "GET /filemanager/dialog.php HTTP/1.1 ...
show more
derorga.de:443 185.185.83.118 - - [30/Oct/2023:07:22:51 +0100] "GET /filemanager/dialog.php HTTP/1.1" 403 6592 "http://derorga.de/filemanager/dialog.php" "Go-http-client/1.1"
show less
Bad Web Bot
๐ฉ๐ช
Trueforce Threat Report
2023-10-30 05:53:29
(2 years ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2023-10-29 21:49:20
(2 years ago)
C1: Web Attack GET /admin/filemanager/dialog.php
Web Spam
Hacking
Bad Web Bot
Web App Attack