๐ฒ๐น
gpet
2024-06-13 08:42:00
(2 years ago)
CVE-2024-4577 exploitation attempt PHP RCE
/index.php/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+ ...
show more
CVE-2024-4577 exploitation attempt PHP RCE
/index.php/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp%3a//input
show less
Hacking
๐บ๐ธ
whitehat
AbuseIPDB Official
2024-06-04 12:39:10
(2 years ago)
Suspicious Operation. Request content:
_method=__construct&method=get&filter[]=printf&get[]=WebBug
Web App Attack
๐บ๐ธ
whitehat
AbuseIPDB Official
2024-06-02 12:15:00
(2 years ago)
Suspicious Operation. Request content:
_method=__construct&method=get&filter[]=printf&get[]=WebBug
Web App Attack
๐จ๐ญ
chr70
2024-06-02 06:51:00
(2 years ago)
SQL injection attempt
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2024-05-26 22:00:27
(2 years ago)
Report By ALSCO Security Team: Potential CSRF Attack Detected
SQL Injection
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2024-05-26 22:00:27
(2 years ago)
Report By Secure Gateway Security Team: XSS Injection Attempt Detected
Web App Attack
๐บ๐ธ
whitehat
AbuseIPDB Official
2024-05-26 17:01:51
(2 years ago)
Suspicious Operation. Request content:
_method=__construct&method=get&filter[]=printf&get[]=WebBug
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2024-05-25 17:54:03
(2 years ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests..
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-21 18:43:23
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:243930) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 21 14:43:16.037304 2024] [security2:error] [pid 27121] [client 2400:8d60:6::9b3e:b81a:63998] [client 2400:8d60:6::9b3e:b81a] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.fitflex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.fitflex.com"] [uri "/"] [unique_id "ZkzrRCb1WFlFwM82f3CRoAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-20 11:23:52
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:243930) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 20 07:23:45.648970 2024] [security2:error] [pid 3203389] [client 2400:8d60:6::9b3e:b81a:60183] [client 2400:8d60:6::9b3e:b81a] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||lusineweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lusineweb.com"] [uri "/"] [unique_id "ZksywdFVUhj9dN-ao4CTAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2024-05-20 06:21:06
(2 years ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-19 23:47:34
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 19 19:47:26.398657 2024] [security2:error] [pid 7592] [client 2400:8d60:6::9b3e:b81a:52093] [client 2400:8d60:6::9b3e:b81a] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||www.alarmnummer.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input: -d allow_url_include=on -d auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "www.alarmnummer.com"] [uri "/"] [unique_id "ZkqPjhRLrGr46KTxO4sidgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
whitehat
AbuseIPDB Official
2024-05-19 13:14:33
(2 years ago)
Suspicious Operation. Request content:
_method=__construct&method=get&filter[]=printf&get[]=WebBug
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-17 16:14:54
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 17 12:14:45.359923 2024] [security2:error] [pid 8521:tid 47455169693440] [client 2400:8d60:6::9b3e:b81a:64806] [client 2400:8d60:6::9b3e:b81a] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||www.aiegroup.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input: -d allow_url_include=on -d auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "www.aiegroup.com"] [uri "/"] [unique_id "ZkeCdTGyawIHdu1KXJ-HCgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-17 11:05:07
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:218420) triggered by 2400:8d60:6::9b3e:b81a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 17 07:05:03.823438 2024] [security2:error] [pid 1303] [client 2400:8d60:6::9b3e:b81a:64398] [client 2400:8d60:6::9b3e:b81a] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||www.urlpick.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input: -d allow_url_include=on -d auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "www.urlpick.com"] [uri "/"] [unique_id "Zkc531yKbeZslpUBFQ9tBQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack