๐บ๐ธ
TPI-Abuse
2025-10-17 07:15:50
(10 months ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 03:15:46.094557 2025] [security2:error] [pid 10410:tid 10410] [client 2a03:2880:f806:1:::51608] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aPHtIhkvZsd-h28-7XHF4gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 18:17:57
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 14:17:54.925818 2025] [security2:error] [pid 899674:tid 899750] [client 2a03:2880:f806:1:::51584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.amphoracollectors.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.amphoracollectors.org"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "aMr7UttdzFyFtLl4JF_F6QAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 23:12:06
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 19:12:01.693068 2025] [security2:error] [pid 8220:tid 8220] [client 2a03:2880:f806:1:::33826] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/263202"] [unique_id "aMNXQTmE9LXosYFOALfjhAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 05:19:51
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 01:19:46.504673 2025] [security2:error] [pid 2348:tid 2348] [client 2a03:2880:f806:1:::60542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Vovaf.dat"] [unique_id "aKf98ontd9Vg9mo9xeBUfgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-08-05 01:54:47
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:1:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:1:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ณ๐ฑ
Roderic
2025-08-04 17:44:34
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ซ๐ท
conseilgouz
2025-08-02 17:18:04
(1 year ago)
ame-Direct access to plugin not allowed
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-22 19:25:32
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 15:25:28.247324 2025] [security2:error] [pid 11400:tid 11400] [client 2a03:2880:f806:1:::34606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alexgitlin.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alexgitlin.com"] [uri "/npp/necromandus.htm/alexgitlin.com"] [unique_id "aH_lqCDjgvzcAQiiMNdtbgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-11 10:58:28
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 11 06:58:23.756182 2025] [security2:error] [pid 3267:tid 3267] [client 2a03:2880:f806:1:::57748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/231511"] [unique_id "aHDuT8E1UstVZqRDUfSMvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-09 18:42:07
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 14:42:01.902915 2025] [security2:error] [pid 30863:tid 30863] [client 2a03:2880:f806:1:::54204] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.pobanz.com|F|4"] [data "REQUEST_URI=/images/christmas17/09/%LqU5eQwTTiloicWKbahtw_thumb_2d93.jpg"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pobanz.com"] [uri "/images/christmas17/09/%LqU5eQwTTiloicWKbahtw_thumb_2d93.jpg"] [unique_id "aG63-QP-RWmdlgml8RpHegAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-28 02:05:54
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 22:05:50.317489 2025] [security2:error] [pid 2737170:tid 2737170] [client 2a03:2880:f806:1:::37088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailyourkayak.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailyourkayak.com"] [uri "/blog/tag/sailyourkayak.com"] [unique_id "aF9N_iDW_CGmwG_NnINFQAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-20 14:09:57
(1 year ago)
(mod_security) mod_security (id:211230) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211230) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 20 10:09:51.913936 2025] [security2:error] [pid 3040579:tid 3040579] [client 2a03:2880:f806:1:::37424] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)(?:\\\\b(?:f(?:tp_(?:nb_)?f?(?:ge|pu)t|get(?:s?s|c)|scanf|write|open|read)|gz(?:(?:encod|writ)e|compress|open|read)|s(?:ession_start|candir)|read(?:(?:gz)?file|dir)|move_uploaded_file|(?:proc_|bz)open|call_user_func)|\\\\$_(?:(?:pos|ge)t|session))\\\\b" at ARGS:ls. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "70"] [id "211230"] [rev "1"] [msg "COMODO WAF: PHP Injection Attack||www.listgene.com|F|2"] [data "Matched Data: FREAD found within ARGS:ls: FREAD"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.listgene.com"] [uri "/cantabria/pgm/liste.php"] [unique_id "aFVrrysuOYVyEsqywwnN_wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-20 05:58:54
(1 year ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 20 01:58:46.676379 2025] [security2:error] [pid 2347146:tid 2347146] [client 2a03:2880:f806:1:::52690] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||becclesrestaurants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "becclesrestaurants.com"] [uri "/wp-includes/js/crop/"] [unique_id "aFT4lnOjlwFS6Ayhr3MBmwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-11 19:57:25
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 11 15:57:19.603963 2025] [security2:error] [pid 1305713:tid 1305713] [client 2a03:2880:f806:1:::59486] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alpha-hk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alpha-hk.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aEnfn3itQSEBeLRiAsHwFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-10 16:31:58
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 10 12:31:53.911936 2025] [security2:error] [pid 3427249:tid 3427249] [client 2a03:2880:f806:1:::36268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blogs.melton.space|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blogs.melton.space"] [uri "/pharisee/index.php/wp-json/wp/v2/users/1"] [unique_id "aEhd-ayn64txdBTidm0tQAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack