|
๐ฎ๐ฉ
hermawan
|
|
[Fri Nov 15 13:18:23.674302 2024] [security2:error] [pid 166678:tid 128488830916288] [client 210.87. ...
show more
[Fri Nov 15 13:18:23.674302 2024] [security2:error] [pid 166678:tid 128488830916288] [client 210.87.125.46:51896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.7.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "63"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /TableFilter/system-v170.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v170.css"] [unique_id "Zzbnr-D-PrkiTzp4p-LumQADAgI"] [staklim-malang.info] [staklim-malang.info] top=[166681] [wP0ZiHUHZV4] [Zzbnr-D-PrkiTzp4p-LumQADAgI] keep_alive=[1] [2024-11-15 13:18:23.674309] [R:Zzbnr-D-PrkiTzp4p-LumQADAgI] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chr
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Sat Nov 09 13:08:28.680629 2024] [security2:error] [pid 1515977:tid 125248030639808] [client 210.87 ...
show more
[Sat Nov 09 13:08:28.680629 2024] [security2:error] [pid 1515977:tid 125248030639808] [client 210.87.125.46:42768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.7.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "62"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /TableFilter/system-v170.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/TableFilter/system-v170.css"] [unique_id "Zy78XN5CtzTf2oEl58nSgwADyhA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1515994] [dfk6sswKKFM] [Zy78XN5CtzTf2oEl58nSgwADyhA] keep_alive=[1] [2024-11-09 13:08:28.680632] [R:Zy78XN5CtzTf2oEl58nSgwADyhA] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Tue Jun 25 16:05:40.554391 2024] [security2:error] [pid 311089:tid 130508300224064] [client 210.87. ...
show more
[Tue Jun 25 16:05:40.554391 2024] [security2:error] [pid 311089:tid 130508300224064] [client 210.87.125.46:53062] [client 210.87.125.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/Ekstrim/2024/05_Mei_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Mei_2024-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/Ekstrim/2024/05_Mei_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Mei_2024-600.webp"] [unique_id "ZnqIZOFu6ixExkSxfyLUMwABoAM"
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Fri Jun 14 10:01:37.866404 2024] [security2:error] [pid 27965:tid 124073562605120] [client 210.87.1 ...
show more
[Fri Jun 14 10:01:37.866404 2024] [security2:error] [pid 27965:tid 124073562605120] [client 210.87.125.46:40966] [client 210.87.125.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/TableFilter/system-v167.css"] [unique_id "ZmuykSXi8_Fz2oKI1wNNXgACyhg"], referer https://staklim-jatim.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[27990] [WJt51aA8B14] [ZmuykSXi8_Fz2oKI1wNNXgACyhg] keep_alive=[1] [2024-06-14 10:01:37.866410] [R:ZmuykSXi8_Fz2oKI1wNNXgACyhg] UA
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Thu Jun 13 19:39:38.859229 2024] [security2:error] [pid 672640:tid 138316150212160] [client 210.87. ...
show more
[Thu Jun 13 19:39:38.859229 2024] [security2:error] [pid 672640:tid 138316150212160] [client 210.87.125.46:33828] [client 210.87.125.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /images/gempa/webp/20240613000123.mmi.jpg.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/gempa/webp/20240613000123.mmi.jpg.webp"] [unique_id "ZmroivNu3TAmClA45GCD7AABpxA"], referer https://staklim-jatim.bmkg.go.id/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-kediri [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[672657] [70jIyqzrEZk] [Z
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Sun Jun 09 09:00:58.617905 2024] [security2:error] [pid 9221:tid 137664015631936] [client 210.87.12 ...
show more
[Sun Jun 09 09:00:58.617905 2024] [security2:error] [pid 9221:tid 137664015631936] [client 210.87.125.46:54830] [client 210.87.125.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,vi;q=0.6,jv;q=0.5,zh-CN;q=0.4,zh;q=0.3 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/TableFilter/system-v167.css"] [unique_id "ZmUM2qlTLNjTBqzT_2EftQAAYxA"], referer https://staklim-jatim.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[9238] [pDY0Z9vTzJc] [ZmUM2qlTLNjTBqzT_2EftQAAYxA] keep_alive=[1] [2024-06-09 09:00:58.617911] [R:ZmUM2qlTLNjTBqzT_2EftQAAYxA] UA:'
...
show less
|
Hacking
Web App Attack
|
|