๐บ๐ธ
TPI-Abuse
2024-08-15 03:26:40
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 23:26:37.567951 2024] [security2:error] [pid 559595:tid 559595] [client 2a03:2880:f806:7:::57008] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ealonline.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ealonline.org"] [uri "/wp-json/wp/v2/users/9"] [unique_id "Zr11bc6pwrX6o-hdvbH0vQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 15:22:24
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 11:22:20.857945 2024] [security2:error] [pid 29627:tid 29627] [client 2a03:2880:f806:7:::52354] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aemcmullin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aemcmullin.com"] [uri "/wp-json/wp/v2/users/4"] [unique_id "Zrt6LFBN3fhNzv9IUFe4kAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 15:06:55
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 11:06:50.457596 2024] [security2:error] [pid 8927:tid 8927] [client 2a03:2880:f806:7:::38064] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pointandshootfilm.com|F|2"] [data ".facebook.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pointandshootfilm.com"] [uri "/www.facebook.com"] [unique_id "Zrt2im_F0W9MW0cLJbxajQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-12 10:55:14
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 12 06:55:09.738958 2024] [security2:error] [pid 7278:tid 7278] [client 2a03:2880:f806:7:::37008] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||superzilla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "superzilla.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrnqDV_kt1M4cfjte_1YzwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-11 14:28:02
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 10:27:59.309849 2024] [security2:error] [pid 9903:tid 9903] [client 2a03:2880:f806:7:::33490] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.penguinexpressmag.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.penguinexpressmag.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrjKb5-0OMsv3TXg3_Lj1gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 10:23:23
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 06:23:21.057393 2024] [security2:error] [pid 30059:tid 30059] [client 2a03:2880:f806:7:::38320] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||akistech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "akistech.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zrc_mdah_X8BliBnGiM5twAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 00:38:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 20:38:04.585501 2024] [security2:error] [pid 32333:tid 32333] [client 2a03:2880:f806:7:::50848] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||faithlines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "faithlines.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zra2bNsouDnyiOBWjHhYiQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 01:09:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 21:09:41.673834 2024] [security2:error] [pid 28051:tid 28051] [client 2a03:2880:f806:7:::54566] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "ZrVsVZ2MbDpsYEsmPqpS9gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 16:58:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 12:58:26.598327 2024] [security2:error] [pid 20765:tid 20783] [client 2a03:2880:f806:7:::36654] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.oldcarz.com|F|2"] [data ".ferrari.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oldcarz.com"] [uri "/www.ferrari.com"] [unique_id "ZrT5MoptFMxOu22gvXJzswAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 05:29:49
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 01:29:41.900931 2024] [security2:error] [pid 734273:tid 734273] [client 2a03:2880:f806:7:::42774] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dailybeautysupply.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dailybeautysupply.com"] [uri "/store/c2/Hair_Care.html/&sa=U&ved=2ahUKEwiA89iT0uzzAhXVbCsKHbeFA2IQFnoECBsQAg&usg=AOvVaw1lKcn-WLWFamr6RcENDbdH/magmi/conf/magmi.ini"] [unique_id "ZrRXxcuAAmlzcst1ZPZI1wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 01:43:29
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 21:43:26.146564 2024] [security2:error] [pid 13613:tid 13613] [client 2a03:2880:f806:7:::39884] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/dj/graphics/DJ_EVENT/Thumbs.db"] [unique_id "ZrQivoQXkXN68kkBqWhh-wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-05 22:20:10
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 18:20:03.375717 2024] [security2:error] [pid 4920:tid 4920] [client 2a03:2880:f806:7:::37046] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/16777"] [unique_id "ZrFQEw1PSGGwl0e0yzqyawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-02 21:06:47
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 02 17:06:42.480080 2024] [security2:error] [pid 3048917:tid 3048917] [client 2a03:2880:f806:7:::53968] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatchristianadventure.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "Zq1KYiq638ackEp8wwscKQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-08-02 18:13:38
(2 years ago)
2024/08/02 20:13:37 [error] 39055#100511: *6385287 limiting requests, excess: 0.461 by zone "crawler ...
show more
2024/08/02 20:13:37 [error] 39055#100511: *6385287 limiting requests, excess: 0.461 by zone "crawler", client: 2a03:2880:f806:7::, server: crxforum.ksol.io, request: "GET /showAnswers.php?topicId=565&commentUniqId=59f6454430621&seed=662f98340bc05 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-30 12:51:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 30 08:51:19.140518 2024] [security2:error] [pid 18371:tid 18376] [client 2a03:2880:f806:7:::53946] [client 2a03:2880:f806:7::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||piazza9.com|F|2"] [data ".buick-reatta.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "piazza9.com"] [uri "/dpiazzadesign.com/www.buick-reatta.com"] [unique_id "ZqjhxyW1HsFzWx0BT8-5KQAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack