πΊπΈ
TPI-Abuse
2024-08-13 10:28:57
(2 years ago)
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 06:28:51.289437 2024] [security2:error] [pid 32389:tid 32389] [client 2a03:2880:f806:1c:::60628] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||www.thecrimsonpirate.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thecrimsonpirate.com"] [uri "/forum/index.php"] [unique_id "Zrs1Y-IHDuzm-_MX68-0IgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-13 06:30:02
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 02:29:54.681842 2024] [security2:error] [pid 16123:tid 16123] [client 2a03:2880:f806:1c:::34018] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nebraskaadaptivesports.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nebraskaadaptivesports.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zrr9YrRG73ctqzeOSdb0XgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-12 01:54:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 21:54:46.365359 2024] [security2:error] [pid 28478:tid 28478] [client 2a03:2880:f806:1c:::57094] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.misscharlottemusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.misscharlottemusic.com"] [uri "/yourweeklylisten/wp-json/wp/v2/users/2"] [unique_id "ZrlrZlllG2KQAOspiiRM9wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-11 22:31:49
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 18:31:42.970774 2024] [security2:error] [pid 8010:tid 8010] [client 2a03:2880:f806:1c:::57004] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimworld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimworld.com"] [uri "/tripoligerlach/[email protected] "] [unique_id "Zrk7zqS2fkxjo4mfHDwpzgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-11 13:06:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 09:06:46.069766 2024] [security2:error] [pid 28487:tid 28487] [client 2a03:2880:f806:1c:::56148] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fruitinthedesert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fruitinthedesert.com"] [uri "/Fruits/wp-json/wp/v2/users/1"] [unique_id "Zri3ZiUb2MnwjPY2CthBNwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-11 12:31:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 08:31:47.384918 2024] [security2:error] [pid 25683:tid 25683] [client 2a03:2880:f806:1c:::49202] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||site.kimbrothersusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "site.kimbrothersusa.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrivMw7kHLl4PveglbND4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-11 07:46:53
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 03:46:48.015883 2024] [security2:error] [pid 24368:tid 24368] [client 2a03:2880:f806:1c:::50718] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.artsy-style.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.artsy-style.com"] [uri "/ART/Thumbs.db"] [unique_id "ZrhsaHPK8bEdEG_96LnnBAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-10 18:17:58
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 14:17:54.278816 2024] [security2:error] [pid 4029:tid 4029] [client 2a03:2880:f806:1c:::57078] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blountmuseum.org|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blountmuseum.org"] [uri "/forms/Thumbs.db"] [unique_id "Zreu0tkmZuSH7K15C4LHawAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-10 08:12:46
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 04:12:42.012570 2024] [security2:error] [pid 1192:tid 1192] [client 2a03:2880:f806:1c:::59280] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robertbanis.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robertbanis.com"] [uri "/3300/download/nchrbs95.dat"] [unique_id "Zrcg-pREVMO3cdwxSeq1VQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 23:30:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 19:30:30.435678 2024] [security2:error] [pid 21109:tid 21109] [client 2a03:2880:f806:1c:::41570] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "ZramlieCslKrOvzSe8UELAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 18:55:46
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 14:55:41.378208 2024] [security2:error] [pid 25238:tid 25238] [client 2a03:2880:f806:1c:::34616] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.virtualmediamasters.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.virtualmediamasters.net"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrZmLXw88rZyUhrzErANcwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 12:59:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 08:59:27.573408 2024] [security2:error] [pid 17540:tid 17540] [client 2a03:2880:f806:1c:::58852] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.furryfriendzy.org|F|2"] [data ".urbandogg.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.furryfriendzy.org"] [uri "/ourFriendz/www.urbandogg.com"] [unique_id "ZrYSr858UMK5M1sEDwT_UQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 10:55:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 06:55:03.332086 2024] [security2:error] [pid 19032:tid 19032] [client 2a03:2880:f806:1c:::38824] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".sinclaircambridge.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0410-william-fitzsimmons-spring-tour-update/www.sinclaircambridge.com"] [unique_id "ZrX1h5DxDY2MhAo_wmzN2AAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 00:50:07
(2 years ago)
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 20:49:58.889449 2024] [security2:error] [pid 2134341:tid 2134341] [client 2a03:2880:f806:1c:::41386] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||furball.global|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "furball.global"] [uri "/g12contactnolog.php"] [unique_id "ZrVntu-C9JMdGRwt6xqCgwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-08 17:23:38
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 13:23:33.953159 2024] [security2:error] [pid 22857:tid 22857] [client 2a03:2880:f806:1c:::55974] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ctrussell.US|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ctrussell.us"] [uri "/search/sql/tables.sql"] [unique_id "ZrT_FXcL6DUlL6vsUChXQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack