πΊπΈ
TPI-Abuse
2024-08-10 20:10:44
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 16:10:38.282370 2024] [security2:error] [pid 1769778:tid 1769778] [client 2a03:2880:f806:19:::51304] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jdeloa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jdeloa.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrfJPrXdXAOj8Ydw_p2oUQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 01:27:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 21:27:47.585927 2024] [security2:error] [pid 12378:tid 12378] [client 2a03:2880:f806:19:::39470] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edgecomix.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrVwkxQzfT0Oq7zCf5ibaQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-08 22:29:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 18:29:31.358363 2024] [security2:error] [pid 6251:tid 6251] [client 2a03:2880:f806:19:::49060] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctorc.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctorc.net"] [uri "/Labs/Lab17/FINDER.DAT"] [unique_id "ZrVGyyCSLfNQrDEG6cOSDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-08 12:52:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 08:52:20.387031 2024] [security2:error] [pid 31912:tid 31912] [client 2a03:2880:f806:19:::39426] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/xxxtubeteens.com"] [unique_id "ZrS_hO8e66ynPkLOsKZmmgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-03 01:52:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 02 21:52:21.542997 2024] [security2:error] [pid 474:tid 474] [client 2a03:2880:f806:19:::55964] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deliverystations.co|F|2"] [data ".artigraphic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deliverystations.co"] [uri "/www.ArtiGraphic.com"] [unique_id "Zq2NVQOK1X0ABxgiXKiKbgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-03 01:31:08
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 02 21:31:05.300118 2024] [security2:error] [pid 6840:tid 6840] [client 2a03:2880:f806:19:::33782] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.amywoodruff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.amywoodruff.com"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "Zq2IWZrheD9GT7aKI3C4ZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-02 18:58:33
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 02 14:58:24.696217 2024] [security2:error] [pid 737937:tid 737959] [client 2a03:2880:f806:19:::39356] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "whatismetamodern.com"] [uri "/wp-json/wp/v2/users/6"] [unique_id "Zq0sULbUw9wIhjtwGV7GUAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2024-08-02 18:20:50
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2024-08-02 18:02:45
(2 years ago)
2024/08/02 20:02:45 [error] 39055#100511: *6381508 limiting requests, excess: 0.205 by zone "crawler ...
show more
2024/08/02 20:02:45 [error] 39055#100511: *6381508 limiting requests, excess: 0.205 by zone "crawler", client: 2a03:2880:f806:19::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&first=900&offset=50&highlight=&seed=662fa7c29ca8c HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-07-30 13:23:11
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 30 09:23:06.172616 2024] [security2:error] [pid 2234:tid 2234] [client 2a03:2880:f806:19:::38982] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.walc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.walc.net"] [uri "/wp-json/wp/v2/users/6"] [unique_id "ZqjpOiay6OSEqGw_0sWf7wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-29 23:44:02
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 29 19:43:59.005202 2024] [security2:error] [pid 30816:tid 30816] [client 2a03:2880:f806:19:::48370] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vangentholding.com|F|2"] [data ".yolasite.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vangentholding.com"] [uri "/uncategorized/f1-betting-korean-grand-prix-picks/cohoiduhoc.yolasite.com"] [unique_id "ZqgpP_bJOvNoWaiz2AGmPwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2024-07-24 07:20:31
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2024-07-24 07:17:30
(2 years ago)
2024/07/24 09:17:30 [error] 25223#101024: *1713147 limiting requests, excess: 0.007 by zone "crawler ...
show more
2024/07/24 09:17:30 [error] 25223#101024: *1713147 limiting requests, excess: 0.007 by zone "crawler", client: 2a03:2880:f806:19::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&action=showComment&commentUniqId=50f66dec70f6f&seed=6691dc519132d HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-07-17 04:46:13
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 17 00:46:06.698563 2024] [security2:error] [pid 1636240:tid 1636240] [client 2a03:2880:f806:19:::54668] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.qualityelevatorcabs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.qualityelevatorcabs.com"] [uri "/[email protected] "] [unique_id "ZpdMjmdMjT7XzMj68lRLpAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-11 05:49:01
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:19:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 11 01:48:54.954017 2024] [security2:error] [pid 30528:tid 47294118397696] [client 2a03:2880:f806:19:::41662] [client 2a03:2880:f806:19::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianasemitruckaccidentlawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianasemitruckaccidentlawyer/%url%"] [unique_id "Zo9yRrU5jSyJi22Ja60H-QAAAhI"]
show less
Brute-Force
Bad Web Bot
Web App Attack