๐บ๐ธ
TPI-Abuse
2024-08-11 21:02:01
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 17:01:53.854048 2024] [security2:error] [pid 15785:tid 15785] [client 2a03:2880:f806:1:::55758] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rootwingcollective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rootwingcollective.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrkmwQXprTp-beigC1svvAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-11 14:02:00
(2 years ago)
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 10:01:53.930452 2024] [security2:error] [pid 14167:tid 14167] [client 2a03:2880:f806:1:::59970] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||depthsofsatan.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depthsofsatan.com"] [uri "/forum/"] [unique_id "ZrjEUUXWJr4pASmPepRptgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 07:02:22
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 03:02:17.867557 2024] [security2:error] [pid 31859:tid 31859] [client 2a03:2880:f806:1:::41196] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "ZrW--W--WlFhb_agKikYcwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 01:44:01
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 21:43:57.618499 2024] [security2:error] [pid 28338:tid 28338] [client 2a03:2880:f806:1:::40518] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".cafe939.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/224-spring-solo-tour-new-album/www.cafe939.com"] [unique_id "ZrV0XWqDxWU4JM3T3KfkzAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 01:08:04
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 21:07:56.792549 2024] [security2:error] [pid 15513:tid 15513] [client 2a03:2880:f806:1:::57804] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users/3"] [unique_id "ZrVr7DdzZOMk0TazEmXSLgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 20:08:15
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 16:08:11.490471 2024] [security2:error] [pid 17698:tid 17698] [client 2a03:2880:f806:1:::40476] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctorc.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctorc.net"] [uri "/Labs/Lab21/FINDER.DAT"] [unique_id "ZrUlq5_9_9VjDlzj5XH7CgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 17:56:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 13:56:05.123309 2024] [security2:error] [pid 5969:tid 5969] [client 2a03:2880:f806:1:::34900] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.famagustacyprus.eu"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrUGtTD6iB5Jd5qCv8BNRAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 17:24:43
(2 years ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 13:24:35.660698 2024] [security2:error] [pid 1983327:tid 1983327] [client 2a03:2880:f806:1:::42546] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||www.cffragrances.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cffragrances.iee-usa.com"] [uri "/wp-includes/js/tinymce/plugins/wpeditimage/"] [unique_id "ZrT_UxSsK301wNHx9PlVnwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-05 18:53:40
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 14:53:32.660222 2024] [security2:error] [pid 12015:tid 12015] [client 2a03:2880:f806:1:::39494] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/9461"] [unique_id "ZrEfrKA1rPExrD6hNh4d9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-08-02 18:38:05
(2 years ago)
2024/08/02 20:38:05 [error] 39055#100511: *6393669 limiting requests, excess: 0.221 by zone "crawler ...
show more
2024/08/02 20:38:05 [error] 39055#100511: *6393669 limiting requests, excess: 0.221 by zone "crawler", client: 2a03:2880:f806:1::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=565&commentUniqId=58ca40df42354&seed=668c660638ba8 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-08-01 16:04:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 01 12:04:28.515658 2024] [security2:error] [pid 6640:tid 6640] [client 2a03:2880:f806:1:::49866] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lionheartpublications.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lionheartpublications.com"] [uri "/[email protected] "] [unique_id "ZquyDH2wCCCBAdWoaq3jQwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-07-24 12:50:15
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-07-24 12:39:16
(2 years ago)
2024/07/24 14:39:16 [error] 25223#101024: *1805437 limiting requests, excess: 0.619 by zone "crawler ...
show more
2024/07/24 14:39:16 [error] 25223#101024: *1805437 limiting requests, excess: 0.619 by zone "crawler", client: 2a03:2880:f806:1::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&action=showComment&commentUniqId=514b8ce89bb06&seed=668be9aff3396 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-20 02:46:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 19 22:46:26.221733 2024] [security2:error] [pid 17169:tid 17169] [client 2a03:2880:f806:1:::54546] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disabilitiestravel.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disabilitiestravel.com"] [uri "/INDEX~1.BAK"] [unique_id "ZpslAvpZV0NkBl0-6BsFsQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-11 16:30:39
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 11 12:30:34.999623 2024] [security2:error] [pid 26220:tid 47408031008512] [client 2a03:2880:f806:1:::43172] [client 2a03:2880:f806:1::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianatriallawyerassociation/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianatriallawyerassociation/%url%"] [unique_id "ZpAIqivNfZzqHr_1V53YOwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack