๐บ๐ธ
TPI-Abuse
2024-08-09 12:59:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 08:59:27.573408 2024] [security2:error] [pid 17540:tid 17540] [client 2a03:2880:f806:1c:::58852] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.furryfriendzy.org|F|2"] [data ".urbandogg.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.furryfriendzy.org"] [uri "/ourFriendz/www.urbandogg.com"] [unique_id "ZrYSr858UMK5M1sEDwT_UQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 10:55:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 06:55:03.332086 2024] [security2:error] [pid 19032:tid 19032] [client 2a03:2880:f806:1c:::38824] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".sinclaircambridge.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0410-william-fitzsimmons-spring-tour-update/www.sinclaircambridge.com"] [unique_id "ZrX1h5DxDY2MhAo_wmzN2AAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 00:50:07
(2 years ago)
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:217291) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 20:49:58.889449 2024] [security2:error] [pid 2134341:tid 2134341] [client 2a03:2880:f806:1c:::41386] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||furball.global|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "furball.global"] [uri "/g12contactnolog.php"] [unique_id "ZrVntu-C9JMdGRwt6xqCgwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 17:23:38
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 13:23:33.953159 2024] [security2:error] [pid 22857:tid 22857] [client 2a03:2880:f806:1c:::55974] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ctrussell.US|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ctrussell.us"] [uri "/search/sql/tables.sql"] [unique_id "ZrT_FXcL6DUlL6vsUChXQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 06:21:56
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 02:21:52.531685 2024] [security2:error] [pid 31001:tid 31001] [client 2a03:2880:f806:1c:::34626] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.darrenj.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.darrenj.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrRkABxzjHpoVaYr-TFvZgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-07 21:41:26
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 17:41:20.244430 2024] [security2:error] [pid 23655:tid 23655] [client 2a03:2880:f806:1c:::54064] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "persnicketyinc.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrPqADUphv_AqDd3tzDyIAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-06 00:52:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 20:52:26.883979 2024] [security2:error] [pid 23652:tid 23652] [client 2a03:2880:f806:1c:::49634] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/40328"] [unique_id "ZrFzylCcnOcFHFcAcKbzCgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-05 05:06:09
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 01:06:01.714194 2024] [security2:error] [pid 8397:tid 8423] [client 2a03:2880:f806:1c:::54960] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianabextralawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianabextralawyer/%url%"] [unique_id "ZrBduaNSyUX6ID6kKAzIgQAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-08-02 23:38:25
(2 years ago)
2024/08/03 01:38:25 [error] 39055#100511: *6517844 limiting requests, excess: 0.266 by zone "crawler ...
show more
2024/08/03 01:38:25 [error] 39055#100511: *6517844 limiting requests, excess: 0.266 by zone "crawler", client: 2a03:2880:f806:1c::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=565&commentUniqId=5a6ce6ca6f0df&seed=662fcb977807c HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-24 21:42:28
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 24 17:42:20.666726 2024] [security2:error] [pid 20255:tid 20255] [client 2a03:2880:f806:1c:::40010] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oneposter.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oneposter.org"] [uri "/wp-json/wp/v2/users/3"] [unique_id "ZqF1PEW7TiQXdW5puET4MAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-07-24 14:50:11
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-07-24 14:28:21
(2 years ago)
2024/07/24 16:28:21 [error] 25223#101024: *1843905 limiting requests, excess: 0.193 by zone "crawler ...
show more
2024/07/24 16:28:21 [error] 25223#101024: *1843905 limiting requests, excess: 0.193 by zone "crawler", client: 2a03:2880:f806:1c::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=565&commentUniqId=50f5c0185c74e&seed=667da0697b1b5 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-20 21:29:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 20 17:29:43.528785 2024] [security2:error] [pid 676:tid 676] [client 2a03:2880:f806:1c:::41642] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Hansen II/Pampa Rouge/Thumbs.db"] [unique_id "ZpwsR4tIFzJYkcV11eGdWQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-20 15:00:03
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 20 10:59:54.625153 2024] [security2:error] [pid 24787:tid 24787] [client 2a03:2880:f806:1c:::60844] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lionheartpublications.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lionheartpublications.com"] [uri "/[email protected] "] [unique_id "ZpvQ6nwYbq6goN8jaWugKgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-18 15:21:25
(2 years ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 18 11:21:17.834900 2024] [security2:error] [pid 291961:tid 291961] [client 2a03:2880:f806:1c:::52666] [client 2a03:2880:f806:1c::] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||www.cffragrances.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cffragrances.iee-usa.com"] [uri "/wp-includes/js/tinymce/themes/advanced/img/"] [unique_id "Zpky7WbxU-GR-nycGoenhwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack