๐บ๐ธ
TPI-Abuse
2025-11-12 12:49:07
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 07:49:04.073211 2025] [security2:error] [pid 8699:tid 8699] [client 2a03:2880:f806:7:::33060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darkalleyproductions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darkalleyproductions.com"] [uri "/darkalleyproductions.com"] [unique_id "aRSCQNhdgPq7OfncWjPjdQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 10:33:29
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 05:33:25.046576 2025] [security2:error] [pid 6992:tid 6992] [client 2a03:2880:f806:7:::57870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cw-enterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cw-enterprises.com"] [uri "/cw-enterprises.com"] [unique_id "aRG_dbHbzhE_3IMR7md2nQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2025-11-07 23:33:07
(10 months ago)
vee-88 : Bloc AI bots=>/sitemap.xml(meta-external)
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-16 14:04:44
(11 months ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 10:04:39.641640 2025] [security2:error] [pid 28019:tid 28019] [client 2a03:2880:f806:7:::39352] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aPD7d7l6CqeHgMT41rMEpQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
cycastic
2025-10-15 22:47:02
(11 months ago)
Probed / on 10/15/2025 22:44:47 +00:00 (UA: meta-externalagent/1.1 (+https://developers.facebook.com ...
show more
Probed / on 10/15/2025 22:44:47 +00:00 (UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler), Query: )
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 17:00:49
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 13:00:44.021031 2025] [security2:error] [pid 22723:tid 22723] [client 2a03:2880:f806:7:::38304] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/325376"] [unique_id "aNwMvLs9EP2mBnjzr3XsVwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-19 02:48:58
(1 year ago)
(mod_security) mod_security (id:211230) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211230) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 18 22:48:52.239186 2025] [security2:error] [pid 19777:tid 19777] [client 2a03:2880:f806:7:::40662] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)(?:\\\\b(?:f(?:tp_(?:nb_)?f?(?:ge|pu)t|get(?:s?s|c)|scanf|write|open|read)|gz(?:(?:encod|writ)e|compress|open|read)|s(?:ession_start|candir)|read(?:(?:gz)?file|dir)|move_uploaded_file|(?:proc_|bz)open|call_user_func)|\\\\$_(?:(?:pos|ge)t|session))\\\\b" at ARGS:ls. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "70"] [id "211230"] [rev "1"] [msg "COMODO WAF: PHP Injection Attack||www.listgene.com|F|2"] [data "Matched Data: FGETS found within ARGS:ls: FGETS"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.listgene.com"] [uri "/cantabria/pgm/liste.php"] [unique_id "aKPmFNJHDYpDUCrLQADBRgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2025-08-18 17:43:51
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. (1100000-173)
show less
Bad Web Bot
๐ณ๐ฑ
Roderic
2025-08-05 02:24:09
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:7:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:7:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ณ๐ฑ
Roderic
2025-08-04 17:49:13
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-30 13:23:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 09:23:34.506036 2025] [security2:error] [pid 18759:tid 18759] [client 2a03:2880:f806:7:::47492] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flavornet.org|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flavornet.org"] [uri "/info/jmol/pdb/6125-24-2.pdb"] [unique_id "aIoc1lNxU6X87BF-auI7uAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2025-07-29 16:36:59
(1 year ago)
ame-Direct access to plugin not allowed
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-23 05:26:41
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 01:26:35.121491 2025] [security2:error] [pid 12399:tid 12399] [client 2a03:2880:f806:7:::50550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alexgitlin.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alexgitlin.com"] [uri "/npp/necromandus.htm/alexgitlin.com"] [unique_id "aIByi2KZU-4UACIoLl-YDgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-13 15:16:20
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 13 11:16:16.227019 2025] [security2:error] [pid 2981:tid 2981] [client 2a03:2880:f806:7:::42508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.technesa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.technesa.com"] [uri "/category/transformacion-industrial/[email protected] "] [unique_id "aHPNwOPeOYgElHCmlllmQwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-10 15:47:50
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 11:47:44.074414 2025] [security2:error] [pid 2889:tid 2889] [client 2a03:2880:f806:7:::47136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/47209"] [unique_id "aG_goIYLX5j4mvRa4wvYTAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack