๐ฉ๐ช
kivitendo.de
2024-09-27 13:38:43
(1 year ago)
[Thu Sep 26 23:41:53.100354 2024] [authz_core:error] [pid 699:tid 140564120946240] [client 209.38.31 ...
show more
[Thu Sep 26 23:41:53.100354 2024] [authz_core:error] [pid 699:tid 140564120946240] [client 209.38.31.53:41202] AH01630: client denied by server configuration: /var/www/kivitendo-erp/.git/config
[Fri Sep 27 15:38:42.112373 2024] [authz_core:error] [pid 153680:tid 139829273880128] [client 209.38.31.53:37632] AH01630: client denied by server configuration: /var/www/kivitendo-erp/.git/config
...
show less
Brute-Force
Web App Attack
๐ธ๐ฌ
babahgroup
2024-09-27 13:37:21
(1 year ago)
(SECURITY-REASON) mod_security (id:210492) triggered by 209.38.31.53 (AU/Australia/-): 3 in the last ...
show more
(SECURITY-REASON) mod_security (id:210492) triggered by 209.38.31.53 (AU/Australia/-): 3 in the last 3600 secs
show less
Brute-Force
๐ฉ๐ช
alliance
2024-09-27 13:30:44
(1 year ago)
27.09.2024 13:30:43 Git repository scan (/.git)
Hacking
Web App Attack
๐ฉ๐ช
lmathe
2024-09-27 13:13:35
(1 year ago)
209.38.31.53 - - [27/Sep/2024:08:43:12 +0200] "GET /.git/config HTTP/1.1" 404 188 "-" "Mozilla/5.0 ( ...
show more
209.38.31.53 - - [27/Sep/2024:08:43:12 +0200] "GET /.git/config HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
209.38.31.53 - - [27/Sep/2024:08:43:13 +0200] "GET /.git/config HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
209.38.31.53 - - [27/Sep/2024:15:13:34 +0200] "GET /.git/config HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
209.38.31.53 - - [27/Sep/2024:15:13:34 +0200] "GET /.git/config HTTP/1.1" 404 188 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 12:24:15
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 08:24:12.146252 2024] [security2:error] [pid 26123:tid 26123] [client 209.38.31.53:39084] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.27"] [uri "/.git/config"] [unique_id "Zvaj7C6x3euXipPojju5CAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2024-09-27 12:15:16
(1 year ago)
[27/Sep/2024:11:25:06.711038 +0100] ZvaIAmPkjPAUjKJfEr996wAAAAU 209.38.31.53 50426 188.246.206.60 70 ...
show more
[27/Sep/2024:11:25:06.711038 +0100] ZvaIAmPkjPAUjKJfEr996wAAAAU 209.38.31.53 50426 188.246.206.60 7080
[27/Sep/2024:13:15:27.990247 +0100] Zvah35ZwhxHiV6nMOnm2YAAAAEw 209.38.31.53 33142 188.246.206.60 7080
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-09-27 10:44:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 06:44:29.183145 2024] [security2:error] [pid 9354:tid 9354] [client 209.38.31.53:40678] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.249"] [uri "/.git/config"] [unique_id "ZvaMjXt-dHP1n_ABvgNhwgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 10:01:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 06:01:18.525972 2024] [security2:error] [pid 9107:tid 9107] [client 209.38.31.53:55684] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.63"] [uri "/.git/config"] [unique_id "ZvaCbjh18isuaCNuHpgwQQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-09-27 09:49:20
(1 year ago)
Fail2Ban triggered
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 08:52:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 04:52:54.763551 2024] [security2:error] [pid 18122:tid 18122] [client 209.38.31.53:51672] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.233"] [uri "/.git/config"] [unique_id "ZvZyZofOjBUysVBO22hPhwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 06:25:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 02:25:50.360841 2024] [security2:error] [pid 19750:tid 19750] [client 209.38.31.53:51220] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.115"] [uri "/.git/config"] [unique_id "ZvZP7hbhISVG_ZdHDavvEQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-09-27 05:38:15
(1 year ago)
Http Port:80 (http_status:403) - /.git/config - Agent:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/53 ...
show more
Http Port:80 (http_status:403) - /.git/config - Agent:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 05:37:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 01:37:13.353968 2024] [security2:error] [pid 28583:tid 28583] [client 209.38.31.53:50678] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.23"] [uri "/.git/config"] [unique_id "ZvZEicrRn36oPefiu7Nf1AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 04:20:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 00:20:24.528603 2024] [security2:error] [pid 32371:tid 32407] [client 209.38.31.53:33956] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.22"] [uri "/.git/config"] [unique_id "ZvYyiPkyYJ0JWgn42N7nZwAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 03:59:14
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.31.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 26 23:59:09.324061 2024] [security2:error] [pid 31541:tid 31541] [client 209.38.31.53:53628] [client 209.38.31.53] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.230"] [uri "/.git/config"] [unique_id "ZvYtjUx1pdhX_S8WjspHfAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack