๐ฌ๐ง
Mendip_Defender
2024-10-23 10:19:13
(1 year ago)
2a03:2880:f806:1:: - - [23/Oct/2024:11:19:13 +0100] "GET /picture.php/20210812_Ixion_Cadwell_25_1673 ...
show more
2a03:2880:f806:1:: - - [23/Oct/2024:11:19:13 +0100] "GET /picture.php/20210812_Ixion_Cadwell_25_1673/tags/701-ixion_at_cadwell HTTP/1.0" 200 3394 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2024-10-06 12:50:03
(1 year ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-10-06 12:21:56
(1 year ago)
2024/10/06 14:21:55 [error] 4235#421416: *3167056 limiting requests, excess: 0.302 by zone "crawler" ...
show more
2024/10/06 14:21:55 [error] 4235#421416: *3167056 limiting requests, excess: 0.302 by zone "crawler", client: 2a03:2880:f806:1::, server: crxforum.ksol.io, request: "GET /showRecAnswers.php?topicId=565&commentUniqId=5df7760559a78&seed=66821f978c5b9 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2024-09-30 09:52:43
(1 year ago)
2a03:2880:f806:1:: - - [30/Sep/2024:10:52:55 +0100] "GET /picture.php/MW_02-12-2012_1336 HTTP/1.0" 2 ...
show more
2a03:2880:f806:1:: - - [30/Sep/2024:10:52:55 +0100] "GET /picture.php/MW_02-12-2012_1336 HTTP/1.0" 200 3289 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-29 09:04:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 29 05:04:32.854244 2024] [security2:error] [pid 24135:tid 24164] [client 2a03:2880:f806:1:::36224] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gafm.org|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gafm.org"] [uri "/www.GAFM.com"] [unique_id "ZvkYIDVaA-xj95kVYkqMNgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2024-09-28 08:52:19
(1 year ago)
2a03:2880:f806:1:: - - [28/Sep/2024:09:52:30 +0100] "GET /picture.php/IC_20150828_2271 HTTP/1.0" 200 ...
show more
2a03:2880:f806:1:: - - [28/Sep/2024:09:52:30 +0100] "GET /picture.php/IC_20150828_2271 HTTP/1.0" 200 3034 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2024-09-25 11:40:52
(2 years ago)
2a03:2880:f806:1:: - - [25/Sep/2024:12:41:03 +0100] "GET /picture.php/20210813_Ixion_Cadwell_25_4030 ...
show more
2a03:2880:f806:1:: - - [25/Sep/2024:12:41:03 +0100] "GET /picture.php/20210813_Ixion_Cadwell_25_4030 HTTP/1.0" 200 3330 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2024-09-19 11:17:14
(2 years ago)
2a03:2880:f806:1:: - - [19/Sep/2024:12:17:24 +0100] "GET /picture.php/MW_27-06-2010_728/category/43 ...
show more
2a03:2880:f806:1:: - - [19/Sep/2024:12:17:24 +0100] "GET /picture.php/MW_27-06-2010_728/category/43 HTTP/1.0" 200 3064 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-08 18:00:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 08 14:00:01.937731 2024] [security2:error] [pid 5111:tid 5111] [client 2a03:2880:f806:1:::38188] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gracefaerie.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gracefaerie.com"] [uri "/Assets/navigation/Thumbs.db"] [unique_id "Zt3mIQ2IR_ZvtV-OmG95xgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-09-03 17:50:21
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-09-03 17:38:34
(2 years ago)
2024/09/03 19:38:33 [error] 50359#783118: *5936848 limiting requests, excess: 0.509 by zone "crawler ...
show more
2024/09/03 19:38:33 [error] 50359#783118: *5936848 limiting requests, excess: 0.509 by zone "crawler", client: 2a03:2880:f806:1::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=688&commentUniqId=63d7c53ea8ab4&seed=6688c948614ee HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-08-21 16:38:54
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 21 12:38:48.440013 2024] [security2:error] [pid 19928:tid 19928] [client 2a03:2880:f806:1:::55526] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chicagowca.com|F|2"] [data ".artadvice.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chicagowca.com"] [uri "/www.artadvice.com"] [unique_id "ZsYYGNNmuGlGfwKzl9MsTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 15:25:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 11:25:42.446491 2024] [security2:error] [pid 23079:tid 23079] [client 2a03:2880:f806:1:::47074] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||post35.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "post35.com"] [uri "/[email protected] "] [unique_id "Zr4d9jwFV8pNA-jsl6aCFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 15:35:39
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 11:35:34.226288 2024] [security2:error] [pid 31609:tid 31609] [client 2a03:2880:f806:1:::50030] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.firstunitedreserve.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.firstunitedreserve.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zrt9Rku6GxS6ysePOjd6jwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 14:43:31
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 10:43:28.258687 2024] [security2:error] [pid 327787:tid 327787] [client 2a03:2880:f806:1:::36496] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||amp712.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "amp712.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrtxEEZ8JcvsfWQbY79FZAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack