|
๐ซ๐ท
dynamix
|
|
Multiple WAF Violations
|
Web App Attack
|
|
|
๐ฒ๐พ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|
|
๐ฎ๐น
VHosting
|
|
Detected mail brute force attack from 4 different servers
|
Brute-Force
|
|
|
๐ง๐ท
Rollcalciferrr
|
|
Passwprd Spray
|
Brute-Force
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Fri Sep 12 16:19:20.722155 2025] [security2:error] [pid 1190665:tid 140661014529728] [client 217.15 ...
show more
[Fri Sep 12 16:19:20.722155 2025] [security2:error] [pid 1190665:tid 140661014529728] [client 217.154.24.80:58928] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %27 found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /pdfjs/web/viewer.html?file=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1 Request URI RAW = /pdfjs/web/viewer.html?file=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), Request Basename = viewer.html"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/pdfjs/web/viewer.html"] [unique_id "aMPlmMKmmP6VSocN_mvIWAAAAkQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1190696] [4JQXJleFWXQ] [aMPlmMKmmP6VSocN_mvIWA
...
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
217.154.24.80 - - [12/Sep/2025:09:18:05 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1% ...
show more
217.154.24.80 - - [12/Sep/2025:09:18:05 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 5984 "https://atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
|
SQL Injection
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Tue Sep 09 15:18:23.176361 2025] [security2:error] [pid 1295947:tid 139979507234496] [client 217.15 ...
show more
[Tue Sep 09 15:18:23.176361 2025] [security2:error] [pid 1295947:tid 139979507234496] [client 217.154.24.80:62681] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %27 found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /pdfjs/web/viewer.html?file=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1 Request URI RAW = /pdfjs/web/viewer.html?file=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), Request Basename = viewer.html"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/pdfjs/web/viewer.html"] [unique_id "aL_iz07jn58HwnBchtKJYgAAA4Y"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1295980] [rnyN8hkmPbk] [aL_iz07jn58HwnBchtKJYg
...
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
217.154.24.80 - - [07/Sep/2025:16:16:15 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1% ...
show more
217.154.24.80 - - [07/Sep/2025:16:16:15 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 709 "https://www.atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
|
SQL Injection
|
|
|
๐บ๐ธ
gu-alvareza
|
|
HTTP.URI.SQL.Injection
|
SQL Injection
Web App Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
Anonymous
|
|
217.154.24.80 - - [05/Sep/2025:13:02:57 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1% ...
show more
217.154.24.80 - - [05/Sep/2025:13:02:57 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 709 "https://www.atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
|
SQL Injection
|
|
|
๐บ๐ธ
gu-alvareza
|
|
HTTP.URI.SQL.Injection
|
SQL Injection
Web App Attack
|
|
|
๐บ๐ธ
fortypoundhead
|
|
SQL Injection Attempt
|
SQL Injection
Web App Attack
|
|