2022-08-12 19:48:25 - Recognized attacks\bad behavior from IP address 195.3.223.239 on port 80 (13 d ...
show more2022-08-12 19:48:25 - Recognized attacks\bad behavior from IP address 195.3.223.239 on port 80 (13 daily hits): Missing User Agent Header, SQL Injection Attack Detected via libinjection, SQL Injection Attack: Common Injection Testing Detected, SQL Injection Attack: SQL Tautology Detected, SQL Injection Attack
show less
[Sat Aug 13 03:31:45.746776 2022] [-:error] [pid 228901:tid 140734954968832] [client 195.3.223.239:5 ...
show more[Sat Aug 13 03:31:45.746776 2022] [-:error] [pid 228901:tid 140734954968832] [client 195.3.223.239:56625] [client 195.3.223.239] ModSecurity: Access denied with code 403 (phase 2). detected SQLi using libinjection with fingerprint 'son),' [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "68"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: son), found within ARGS:id: 'nvOpzp; AND 1=1 OR (<'\\x22>iKO)),"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "Yva4sV8CmLMHjwmcOMuNtgAAAHw"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[229017] [u+6vK6EbtMk] [Yva4sV8CmLMHjwmcOMuNtgAAAHw] keep_alive=[0] [2022-08-13 03:31:45.746783]
...
show less
Hacking
Web App Attack
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 195.3.223.239 (PL/Poland/-/-/server237. ...
show more(mod_security) mod_security triggered on hostname [redacted] 195.3.223.239 (PL/Poland/-/-/server237.seasonaldiffer.me)
show less