๐ฏ๐ต
zwh
2024-02-23 23:50:48
(2 years ago)
Attack for XMLRPC
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2024-02-23 06:12:19
(2 years ago)
18 attacks on PHP URLs, Wordpress URLs:
GET //xmlrpc.php?rsd HTTP/1.1
GET //sito/wp-includes/wlwmani ...
show more
18 attacks on PHP URLs, Wordpress URLs:
GET //xmlrpc.php?rsd HTTP/1.1
GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1
show less
Web App Attack
๐ฎ๐ฉ
setup
2024-02-22 16:26:40
(2 years ago)
/wp-includes/wlwmanifest.xml
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-22 16:07:53
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 22 11:07:49.719406 2024] [security2:error] [pid 18528:tid 47191921329920] [client 206.189.150.26:55211] [client 206.189.150.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sloveniaflyfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sloveniaflyfishing.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZddxVV9Yc_uepMgh5v5QXAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
mangomad
2024-02-22 16:00:52
(2 years ago)
Repeated Apache mod_security rule triggers
Brute-Force
Web App Attack
๐ฌ๐ง
Swiptly
2024-02-22 15:50:27
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2024-02-22 15:11:57
(2 years ago)
206.189.150.26 - - [22/Feb/2024:16:11:54 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 798 "-" "Mozilla ...
show more
206.189.150.26 - - [22/Feb/2024:16:11:54 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 798 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
206.189.150.26 - - [22/Feb/2024:16:11:55 +0100] "GET //wp-json/wp/v2/users/ HTTP/1.1" 404 144 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
206.189.150.26 - - [22/Feb/2024:16:11:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Web App Attack
๐ฆ๐บ
MAGIC
2024-02-22 14:07:56
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฌ๐ง
noise.agency
2024-02-22 13:48:22
(2 years ago)
(wordpress) Failed wordpress login from 206.189.150.26 (SG/Singapore/-)
Brute-Force
๐ง๐ช
taivas.nl
2024-02-22 13:32:19
(2 years ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
Major Hostility
2024-02-22 12:03:06
(2 years ago)
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-inc ...
show more
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404
show less
Web App Attack
๐ฉ๐ช
stinpriza
2024-02-22 10:05:41
(2 years ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-22 09:54:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 22 04:54:28.997847 2024] [security2:error] [pid 2937] [client 206.189.150.26:51110] [client 206.189.150.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.localpetsitters.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZdcZ1PylqEi0mtxcmZc-NQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
JCB
2024-02-22 09:38:00
(2 years ago)
/wp-includes/wlwmanifest.xml
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-22 09:34:55
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 206.189.150.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 22 04:34:51.011915 2024] [security2:error] [pid 21537] [client 206.189.150.26:61893] [client 206.189.150.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.idahostem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.idahostem.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZdcVO3HVKRHO3oIOBdERfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack