Anonymous
|
|
Excessive crawling/scraping
|
Hacking
Brute-Force
|
|
Anonymous
|
|
Excessive crawling/scraping
|
Hacking
Brute-Force
|
|
hermawan
|
|
[Sat Jun 08 12:07:14.486005 2024] [security2:error] [pid 93147:tid 135111047644736] [client 192.0.11 ... show more[Sat Jun 08 12:07:14.486005 2024] [security2:error] [pid 93147:tid 135111047644736] [client 192.0.113.147:36630] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "38"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZmPnAvdQXzJINXsIY-_I5gAAAI8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[93204] [4Vmq4ymN73M] [ZmPnAvdQXzJINXsIY-_I5gAAAI8] keep_alive=[0] [2024-06-08 12:07:14.486009] [R:ZmPnAvdQXzJINXsIY-_I5gAAAI8] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, applicatio
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Mon Jun 03 06:29:18.079025 2024] [security2:error] [pid 358343:tid 134340793075264] [client 192.0.1 ... show more[Mon Jun 03 06:29:18.079025 2024] [security2:error] [pid 358343:tid 134340793075264] [client 192.0.113.147:55946] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "37"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "Zl0ATggTIKUD-6gqQwG46AAAAMY"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[358391] [0tTjlcBkdlA] [Zl0ATggTIKUD-6gqQwG46AAAAMY] keep_alive=[0] [2024-06-03 06:29:18.079029] [R:Zl0ATggTIKUD-6gqQwG46AAAAMY] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, applicat
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Tue Feb 27 04:17:08.274639 2024] [security2:error] [pid 758733:tid 124209000875584] [client 192.0.1 ... show more[Tue Feb 27 04:17:08.274639 2024] [security2:error] [pid 758733:tid 124209000875584] [client 192.0.113.147:55954] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "18"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "Zdz_1C8SpHAmXHUC7VczGgAAAM8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[758777] [X9ChbldHJqg] [Zdz_1C8SpHAmXHUC7VczGgAAAM8] keep_alive=[0] [2024-02-27 04:17:08.274643] [R:Zdz_1C8SpHAmXHUC7VczGgAAAM8] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, applicat
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Thu Jan 04 10:47:27.242532 2024] [security2:error] [pid 39653:tid 139670910391872] [client 192.0.11 ... show more[Thu Jan 04 10:47:27.242532 2024] [security2:error] [pid 39653:tid 139670910391872] [client 192.0.113.147:40418] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "6"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZZYqT-fvXJOe0gGFY3OvOwAAAJM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[39762] [fYYUl+5WKgI] [ZZYqT-fvXJOe0gGFY3OvOwAAAJM] keep_alive=[0] [2024-01-04 10:47:27.242536] [R:ZZYqT-fvXJOe0gGFY3OvOwAAAJM] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, application
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sat Nov 11 19:22:02.434156 2023] [security2:error] [pid 498945:tid 140515894883904] [client 192.0.1 ... show more[Sat Nov 11 19:22:02.434156 2023] [security2:error] [pid 498945:tid 140515894883904] [client 192.0.113.147:60930] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZU9x6vxYbNcG_2sj5PGm9QAAAJs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[499087] [Tgn0ex+zaGY] [ZU9x6vxYbNcG_2sj5PGm9QAAAJs] keep_alive=[0] [2023-11-11 19:22:02.434163] [R:ZU9x6vxYbNcG_2sj5PGm9QAAAJs] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, application
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Wed Nov 08 15:59:07.829846 2023] [security2:error] [pid 414402:tid 139677545776704] [client 192.0.1 ... show more[Wed Nov 08 15:59:07.829846 2023] [security2:error] [pid 414402:tid 139677545776704] [client 192.0.113.147:45912] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZUtN28oOStGXQMT4ZunGZgAAACU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[414526] [UEnETOAMol8] [ZUtN28oOStGXQMT4ZunGZgAAACU] keep_alive=[0] [2023-11-08 15:59:07.829849] [R:ZUtN28oOStGXQMT4ZunGZgAAACU] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, application
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Tue Oct 31 06:05:39.571074 2023] [security2:error] [pid 295845:tid 140234641634880] [client 192.0.1 ... show more[Tue Oct 31 06:05:39.571074 2023] [security2:error] [pid 295845:tid 140234641634880] [client 192.0.113.147:64098] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZUA2wzOsWdz9Ze5yyoaDFQAAAIY"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[295966] [nXOeE3e7Occ] [ZUA2wzOsWdz9Ze5yyoaDFQAAAIY] keep_alive=[0] [2023-10-31 06:05:39.571079] [R:ZUA2wzOsWdz9Ze5yyoaDFQAAAIY] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, application
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sun Oct 22 06:30:57.714567 2023] [security2:error] [pid 834950:tid 140598858192448] [client 192.0.1 ... show more[Sun Oct 22 06:30:57.714567 2023] [security2:error] [pid 834950:tid 140598858192448] [client 192.0.113.147:58670] [client 192.0.113.147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: wp.com feedbot/1.0 (+https://wp.com) request_line = GET /index.php?format=feed&type=rss HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZTRfMVTURiLis8yUjbFghAAAAOo"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[835071] [0T6JYTLoxPE] [ZTRfMVTURiLis8yUjbFghAAAAOo] keep_alive=[0] [2023-10-22 06:30:57.714570] [R:ZTRfMVTURiLis8yUjbFghAAAAOo] UA:'wp.com feedbot/1.0 (+https://wp.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'application/atom+xml, application/rss+xml, application
... show less
|
Hacking
Web App Attack
|
|
Anonymous
|
|
Excessive crawling/scraping
|
Hacking
Brute-Force
|
|
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
Anonymous
|
|
Excessive crawling/scraping
|
Hacking
Brute-Force
|
|
MAGIC
|
|
Distributed DDOS attempts for multiple sites
|
DDoS Attack
Bad Web Bot
|
|