๐ซ๐ท
SpaceHost-Server
2026-09-29 22:21:04
(21 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
ใใใจใใใใ
2026-09-29 05:40:13
(1 day ago)
Automated exploitation attempt of WordPress CVE-2026-87902 (unauthenticated path traversal in page-t ...
show more
Automated exploitation attempt of WordPress CVE-2026-87902 (unauthenticated path traversal in page-template resolution, GHSA-7hp8-65ch-5whp) against a self-hosted nginx web service. Double-encoded pagename traversal probes targeting local PHP file inclusion (pearcmd.php oracle variants included). Self-hosted service; no site identifiers included.
show less
Hacking
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-26 13:51:35
(4 days ago)
Web scanning / probing for vulnerable paths | URL: /?page_id=85109&pagename=templates%252F..%252F..% ...
show more
Web scanning / probing for vulnerable paths | URL: /?page_id=85109&pagename=templates%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fopt%252Fcpanel%252Fea-php81%252Froot%252Fusr%252Fshare%252Fpear%252Fpearcmd.php%20+config-list | Evidence: 188.165.193.125 - - [26/Sep/2026:15:51:09 +0200] \"GET /?page_id=85109&pagename=templates%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fopt%252Fcpanel%252Fea-php81%252Froot%252Fusr%252Fshare%252Fpear%252Fpearcmd.php%20+config-list HTTP/1.1\" 403 199 \"-\" \"Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)\" GEOIP_COUNTRY_CODE=FR | ASN: OVH SAS | Country: FR
show less
Port Scan
Web App Attack
๐ซ๐ฎ
etasoft
2026-09-26 11:16:12
(4 days ago)
Auto-blocked by WP Security AI: Rate limit: 3 violaciones
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-26 01:27:34
(4 days ago)
Path Traversal Attack (/../) or (/.../). Pattern match "(?i)(?: (930100-197)
Hacking
๐ช๐ธ
robotstxt
2026-09-25 23:22:03
(4 days ago)
188.165.193.125 - - [25/Sep/2026:23:21:55 +0000] "GET /?page_id=1&pagename=templates%252F..%252F..%2 ...
show more
188.165.193.125 - - [25/Sep/2026:23:21:55 +0000] "GET /?page_id=1&pagename=templates%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fopt%252Falt%252Fphp74%252Fusr%252Fshare%252Fpear%252Fpearcmd.php%20+config-list HTTP/1.1" 403 5 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "127.0.5.4" edge="188.165.193.125"
188.165.193.125 - - [25/Sep/2026:23:21:56 +0000] "GET /?page_id=2&pagename=templates%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fopt%252Falt%252Fphp74%252Fusr%252Fshare%252Fpear%252Fpearcmd.php%20+config-list HTTP/1.1" 403 5 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "127.0.2.7" edge="188.165.193.125"
188.165.193.125 - - [25/Sep/2026:23:21:56 +0000] "GET /?page_id=3&pagename=templates%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fopt%252Falt%252Fphp74%252Fusr%252Fshare%252Fpear%252Fpearcmd.php%20+config-list HTTP/1.1" 403 5 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bo
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-25 19:48:34
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-25 12:55:28
(5 days ago)
Modsecurity: probe or injection attempt
SQL Injection
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-25 01:01:34
(5 days ago)
[Fri Sep 25 11:01:33.156840 2026] [security2:error] [pid 588529] [client 188.165.193.125:37366] [cli ...
show more
[Fri Sep 25 11:01:33.156840 2026] [security2:error] [pid 588529] [client 188.165.193.125:37366] [client 188.165.193.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/"] [unique_id "arXH7UZawmjgpUas3hw-lwAAAAA"]
...
show less
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:59:25
(6 days ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 01:52:54
(6 days ago)
Web scanning / probing for vulnerable paths | URL: /?page_id=8 | Evidence: 188.165.193.125 - - [24/S ...
show more
Web scanning / probing for vulnerable paths | URL: /?page_id=8 | Evidence: 188.165.193.125 - - [24/Sep/2026:03:52:34 +0200] \"POST /?page_id=8 HTTP/1.1\" 404 43675 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=FR | ASN: OVH SAS | Country: FR
show less
Port Scan
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:02:06
(6 days ago)
8.225 post requests in 1 hour (2w9h55m)
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-24 00:40:06
(6 days ago)
Request content type is not allowed by policy. Match of "within %{tx.allowed_request_content_type}" ...
show more
Request content type is not allowed by policy. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. (920420-201)
show less
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-24 00:28:02
(6 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-09-23 22:44:59
(6 days ago)
[Thu Sep 24 08:44:58.863525 2026] [security2:error] [pid 435687] [client 188.165.193.125:49330] [cli ...
show more
[Thu Sep 24 08:44:58.863525 2026] [security2:error] [pid 435687] [client 188.165.193.125:49330] [client 188.165.193.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/"] [unique_id "arRWauRs0jIqrf8j_bZ4RAAAAAQ"]
...
show less
Web App Attack