๐บ๐ธ
masterguru
2025-08-18 17:34:24
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. (1100000-173)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-16 18:35:59
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 16 14:35:54.555314 2025] [security2:error] [pid 25133:tid 25133] [client 2a03:2880:f806:10:::42082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flavornet.org|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flavornet.org"] [uri "/info/jmol/pdb/10208-80-7.pdb"] [unique_id "aKDPihN-zHzilc4vz5xVagAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-08-05 02:47:14
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:10:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:10:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-08-05 02:04:05
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 04 22:04:01.627853 2025] [security2:error] [pid 893080:tid 894139] [client 2a03:2880:f806:10:::33844] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tkfay.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aJFmkdmpbTeGvauBD8wu4AAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-08-04 18:12:23
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-25 00:42:17
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 24 20:42:13.706912 2025] [security2:error] [pid 22862:tid 22862] [client 2a03:2880:f806:10:::60374] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||beckersystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "beckersystems.net"] [uri "/beckerwiki/index.php"] [unique_id "aILS5eRDUFmdqGRKVkThmQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-16 20:32:14
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 16:32:06.669948 2025] [security2:error] [pid 779:tid 779] [client 2a03:2880:f806:10:::34316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/51446"] [unique_id "aHgMRqjQkkb-yRXki0EgEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-19 21:14:00
(1 year ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 19 17:13:56.130808 2025] [security2:error] [pid 1938533:tid 1938533] [client 2a03:2880:f806:10:::48008] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||becclesrestaurants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "becclesrestaurants.com"] [uri "/wp-includes/js/dist/vendor/"] [unique_id "aFR9lF4xrjHJQ7gHXBgTJgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-14 01:17:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 13 21:17:32.307611 2025] [security2:error] [pid 1873450:tid 1873450] [client 2a03:2880:f806:10:::50226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailyourkayak.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailyourkayak.com"] [uri "/blog/tag/sailyourkayak.com"] [unique_id "aEzNrKfvIV7Jd-KLB1KxAQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-03 16:50:04
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 03 12:49:56.112897 2025] [security2:error] [pid 1821448:tid 1821448] [client 2a03:2880:f806:10:::55176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.surviquo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.surviquo.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aD8ntKv36raRccmibb3N4gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-03 04:14:18
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 03 00:14:11.087757 2025] [security2:error] [pid 34066:tid 34066] [client 2a03:2880:f806:10:::57548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aD52kyECpo3dKd_tXkW-YwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-28 02:24:42
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 27 22:24:36.682267 2025] [security2:error] [pid 1051479:tid 1051479] [client 2a03:2880:f806:10:::45354] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||websitesforauthors.design|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "websitesforauthors.design"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aDZz5B-HxPCDfgODqB08agAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-24 12:28:02
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 24 08:27:57.165546 2025] [security2:error] [pid 3118905:tid 3118905] [client 2a03:2880:f806:10:::56082] [client 2a03:2880:f806:10::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.idodat.com|F|2"] [data ".php.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.idodat.com"] [uri "/index.php.OLD"] [unique_id "aDG7TbNfJqwJwZTWE00RCwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-15 10:15:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 06:15:05.074553 2025] [security2:error] [pid 227540:tid 227540] [client 2a03:2880:f806:10:::41370] [client 2a03:2880:f806:10::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blog.freedrm.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blog.freedrm.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aCW-qYws9vPsHMAbT4ZVxAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-15 01:26:42
(1 year ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:10:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 14 21:26:36.083466 2025] [security2:error] [pid 1418525:tid 1418525] [client 2a03:2880:f806:10:::52436] [client 2a03:2880:f806:10::] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aCVCzJrwhmx-8UR72S53wQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack