๐บ๐ธ
TPI-Abuse
2025-07-10 04:34:21
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 00:34:16.657225 2025] [security2:error] [pid 28427:tid 28427] [client 2a03:2880:f806:1b:::33360] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.pobanz.com|F|4"] [data "REQUEST_URI=/images/christmas17/08/L4+Z62UERi68H6c2h+M%lQ_thumb_2d66.jpg"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pobanz.com"] [uri "/images/christmas17/08/L4+Z62UERi68H6c2h+M%lQ_thumb_2d66.jpg"] [unique_id "aG9CyKK7I8PTT_pA4FKT9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-08 21:26:03
(1 year ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 17:25:57.927077 2025] [security2:error] [pid 15706:tid 15706] [client 2a03:2880:f806:1b:::51210] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||becclesrestaurants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "becclesrestaurants.com"] [uri "/wp-includes/js/tinymce/plugins/wpview/"] [unique_id "aG2M5VPq2zGkgfuRvf20bgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-08 15:53:59
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 11:53:52.835578 2025] [security2:error] [pid 22121:tid 22121] [client 2a03:2880:f806:1b:::52290] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.kentsmithfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.kentsmithfamily.com"] [uri "/index.php"] [unique_id "aG0_EHOPoqacPWkl1_1noQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-07 22:34:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 18:34:29.855145 2025] [security2:error] [pid 10747:tid 10747] [client 2a03:2880:f806:1b:::48620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alexgitlin.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alexgitlin.com"] [uri "/npp/necromandus.htm/alexgitlin.com"] [unique_id "aGxLdW0NVYR0KYeKHQk_0AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-03 05:21:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 03 01:21:03.821566 2025] [security2:error] [pid 109027:tid 109027] [client 2a03:2880:f806:1b:::60954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aD6GP9prjyM3hzqoR0P5JwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-23 02:53:14
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 22:53:10.845212 2025] [security2:error] [pid 2468237:tid 2468237] [client 2a03:2880:f806:1b:::48922] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adoniahenterprises.com"] [uri "/goober_.htaccess.preinstall"] [unique_id "aC_jFs1W_T9jlZCbshUwtgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-22 14:22:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 10:22:41.715614 2025] [security2:error] [pid 3618966:tid 3618966] [client 2a03:2880:f806:1b:::49066] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chicmeow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chicmeow.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aC8zMf1Dg9tglc8NiJtIBAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-22 08:44:16
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 04:44:12.235882 2025] [security2:error] [pid 1126501:tid 1126582] [client 2a03:2880:f806:1b:::40290] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.digital4z.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.digital4z.com"] [uri "/Digital4z.com/wp-admin/css/colors/midnight/WS_FTP.LOG"] [unique_id "aC7j3N6C8-h9Mz3XfWKM1gAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-25 07:07:00
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 03:06:53.556066 2025] [security2:error] [pid 188880:tid 188880] [client 2a03:2880:f806:1b:::59864] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.five21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.five21.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aAs0jekgWALben-6-9zUOQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-17 06:42:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 17 02:42:35.920693 2025] [security2:error] [pid 15722:tid 15722] [client 2a03:2880:f806:1b:::34264] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutinsignia.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/images/WS_FTP.LOG"] [unique_id "aACi22dsn9utD428Zi2CXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-16 14:58:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 16 10:58:08.804343 2025] [security2:error] [pid 1809442:tid 1809442] [client 2a03:2880:f806:1b:::54626] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/91162"] [unique_id "Z__FgE2wC4ebl0S5kahb9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-30 16:55:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 12:55:29.725647 2025] [security2:error] [pid 15400:tid 15400] [client 2a03:2880:f806:1b:::38134] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greenroomonline.org|F|2"] [data ".pvpnwestmont.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greenroomonline.org"] [uri "/www.pvpnwestmont.com"] [unique_id "Z-l3geadvvN1OW-CWGk87QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 14:47:57
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 10:47:50.189540 2025] [security2:error] [pid 27873:tid 27873] [client 2a03:2880:f806:1b:::59984] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.williamfitzsimmons.com|F|2"] [data ".forum-bielefeld.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.williamfitzsimmons.com"] [uri "/www.forum-bielefeld.com"] [unique_id "Z-QTlkIiYLXEGMNma2xdAwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 01:01:11
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 20:01:04.972764 2025] [security2:error] [pid 24490:tid 24490] [client 2a03:2880:f806:1b:::60544] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.raintechgutters.com|F|2"] [data ".raintechgutters.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.raintechgutters.com"] [uri "/who-does-gutter-installation-near-me-for-a-couple-of-seconds-gutterinstallation/www.raintechgutters.com"] [unique_id "Z7fQUIt9E6f7s3lG0qaGmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-27 21:42:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 27 16:42:41.114361 2025] [security2:error] [pid 4176:tid 4202] [client 2a03:2880:f806:1b:::60980] [client 2a03:2880:f806:1b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.newtrendmag.org|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.newtrendmag.org"] [uri "/(http:/peacepalestine.blogspot.com"] [unique_id "Z5f90YvThFeSPDHneeEcRQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack