๐ฌ๐ง
Mendip_Defender
2024-09-29 10:05:24
(2 years ago)
2a03:2880:f806:14:: - - [29/Sep/2024:11:05:37 +0100] "GET /picture.php/MW_29-06-2008_0586 HTTP/1.0" ...
show more
2a03:2880:f806:14:: - - [29/Sep/2024:11:05:37 +0100] "GET /picture.php/MW_29-06-2008_0586 HTTP/1.0" 200 3266 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2024-09-26 18:39:17
(2 years ago)
2a03:2880:f806:14:: - - [26/Sep/2024:19:39:29 +0100] "GET /picture.php/161639/tags/837-barn HTTP/1.0 ...
show more
2a03:2880:f806:14:: - - [26/Sep/2024:19:39:29 +0100] "GET /picture.php/161639/tags/837-barn HTTP/1.0" 200 3193 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-25 12:12:25
(2 years ago)
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 25 08:12:18.784126 2024] [security2:error] [pid 29786:tid 29786] [client 2a03:2880:f806:14:::46994] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||jeffersonlynn.com|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "jeffersonlynn.com"] [uri "/g12privacy.php"] [unique_id "ZvP-InLz-2CmRzqufa3KFgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2024-09-19 10:19:16
(2 years ago)
2a03:2880:f806:14:: - - [19/Sep/2024:11:19:25 +0100] "GET /picture.php/MW_10-03-2013_0787/category/1 ...
show more
2a03:2880:f806:14:: - - [19/Sep/2024:11:19:25 +0100] "GET /picture.php/MW_10-03-2013_0787/category/191 HTTP/1.0" 200 3233 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-04 09:09:14
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 04 05:09:10.345858 2024] [security2:error] [pid 23881:tid 23881] [client 2a03:2880:f806:14:::35734] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pages4you.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pages4you.com"] [uri "/default.old"] [unique_id "Ztgjtk_VZF3nXov5H3vtpwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-09-03 17:50:16
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-09-03 17:27:11
(2 years ago)
2024/09/03 19:27:10 [error] 50359#783118: *5932074 limiting requests, excess: 0.088 by zone "crawler ...
show more
2024/09/03 19:27:10 [error] 50359#783118: *5932074 limiting requests, excess: 0.088 by zone "crawler", client: 2a03:2880:f806:14::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=5&commentUniqId=631c521076b86&seed=66cc058062787 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-02 09:33:10
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 02 05:33:05.625819 2024] [security2:error] [pid 5913:tid 5913] [client 2a03:2880:f806:14:::55044] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kulacenterky.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kulacenterky.com"] [uri "/2015/11/[email protected] "] [unique_id "ZtWGUTMQPtQaq0TACwQMKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2024-08-30 22:24:49
(2 years ago)
2a03:2880:f806:14:: - - [30/Aug/2024:23:24:52 +0100] "GET /picture.php/MW_09-09-2012_0881/tags/68-ha ...
show more
2a03:2880:f806:14:: - - [30/Aug/2024:23:24:52 +0100] "GET /picture.php/MW_09-09-2012_0881/tags/68-hare_hounds HTTP/1.0" 200 3403 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-08-24 14:08:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 24 10:08:21.214468 2024] [security2:error] [pid 24855:tid 24876] [client 2a03:2880:f806:14:::50328] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||haulitoff.com|F|2"] [data ".html.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haulitoff.com"] [uri "/latina_teens/index.html.com"] [unique_id "ZsnpVd7RJdbMQHHwmcDCpAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-22 03:59:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 21 23:59:40.697487 2024] [security2:error] [pid 23567:tid 23567] [client 2a03:2880:f806:14:::43290] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sprektech.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sprektech.com"] [uri "/nova/cgi-bin/class/CSC/33qrpu27.dat"] [unique_id "Zsa3rNBaewUMYszf66xzfwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 15:57:39
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 19 11:57:34.886803 2024] [security2:error] [pid 17208:tid 17208] [client 2a03:2880:f806:14:::54628] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.healingworksmassage.studio|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.healingworksmassage.studio"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZsNrbgjp8XtRoBHYJS62NgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 16:45:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 12:45:21.928616 2024] [security2:error] [pid 3378:tid 3378] [client 2a03:2880:f806:14:::40008] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.staben.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.staben.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zr-CIc4jDmGDYLokuEf5DAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 11:44:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 07:44:21.969088 2024] [security2:error] [pid 815937:tid 816009] [client 2a03:2880:f806:14:::44318] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||killyourattitude.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "killyourattitude.com"] [uri "/[email protected] "] [unique_id "Zr87lT9CPyF5WcvmszsROQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-14 23:44:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:14:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 19:44:37.222775 2024] [security2:error] [pid 8604:tid 8604] [client 2a03:2880:f806:14:::37094] [client 2a03:2880:f806:14::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.borzois.com|F|2"] [data ".batw.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.borzois.com"] [uri "/www.BATW.com"] [unique_id "Zr1BZU_Qhy6ubYmxf2RyxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack