πΊπΈ
TPI-Abuse
2024-08-11 23:10:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 19:10:38.038696 2024] [security2:error] [pid 5515:tid 5515] [client 2a03:2880:f806:9:::55194] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctorc.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctorc.net"] [uri "/Labs/Lab11/EAR/FINDER.DAT"] [unique_id "ZrlE7vmm-z2uCgSs-w_qOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-10 01:26:17
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 21:26:11.711572 2024] [security2:error] [pid 24313:tid 24313] [client 2a03:2880:f806:9:::58698] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.starvationacres.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.starvationacres.us"] [uri "/wp-json/wp/v2/users/2"] [unique_id "ZrbBs9cfG3No_oBgTW6QuwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 20:09:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 16:09:21.281813 2024] [security2:error] [pid 14550:tid 14550] [client 2a03:2880:f806:9:::50702] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scrunchiebuttbikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scrunchiebuttbikinis.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrZ3ccWwxwiEmrOhtmXwAwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 17:39:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 13:39:22.181300 2024] [security2:error] [pid 32434:tid 32434] [client 2a03:2880:f806:9:::55680] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.snapdragonworkshops.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.snapdragonworkshops.com"] [uri "/[email protected] "] [unique_id "ZrZUSlIIrrEFmbeUDlIsTgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 15:17:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 11:17:02.194144 2024] [security2:error] [pid 19448:tid 19448] [client 2a03:2880:f806:9:::53254] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.timberwolf-construction.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.timberwolf-construction.com"] [uri "/mail to: [email protected] "] [unique_id "ZrYy7ts41HgaXNzzXMEJcQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 14:38:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 10:38:05.180795 2024] [security2:error] [pid 10087:tid 10087] [client 2a03:2880:f806:9:::45252] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||encoremtmorris.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "encoremtmorris.com"] [uri "/info/page-23/[email protected] "] [unique_id "ZrYpzUmX4WP04eE0UOzefAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 12:25:10
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 08:25:05.837770 2024] [security2:error] [pid 2802495:tid 2802495] [client 2a03:2880:f806:9:::34932] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||comics.flyingdodostudio.com|F|2"] [data ".tumblr.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "comics.flyingdodostudio.com"] [uri "/theautovoyuerist/inkyphalangies.tumblr.com"] [unique_id "ZrYKobtC6AHut0dk1i5RyQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 09:54:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 05:54:42.670122 2024] [security2:error] [pid 22423:tid 22423] [client 2a03:2880:f806:9:::50692] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.grasslakepizzatime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.grasslakepizzatime.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrXnYsMX4CUCDIrsCPBuOQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 04:12:36
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 00:12:33.032832 2024] [security2:error] [pid 5701:tid 5701] [client 2a03:2880:f806:9:::54588] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brbcash.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brbcash.com"] [uri "/index.php/wp-json/wp/v2/users/1"] [unique_id "ZrWXMUU1dhCQPGT3tOQ5cAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 02:15:17
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 22:15:13.482632 2024] [security2:error] [pid 1656814:tid 1656814] [client 2a03:2880:f806:9:::48790] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gsrsv.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gsrsv.org"] [uri "/springtimeinc.com"] [unique_id "ZrV7sUZFovsewjLP6GEb4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-08 19:03:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 15:02:53.887410 2024] [security2:error] [pid 10888:tid 10888] [client 2a03:2880:f806:9:::34126] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/zoomfrankfurt.com"] [unique_id "ZrUWXVf52R7ARKdUP0ZeXAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-07 00:08:29
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 06 20:08:24.543288 2024] [security2:error] [pid 4345:tid 4465] [client 2a03:2880:f806:9:::39946] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianakidneydamagelawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianakidneydamagelawyer/%url%"] [unique_id "ZrK6-Aj620jjQGfZLzLLpAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2024-08-02 19:39:46
(2 years ago)
2024/08/02 21:39:46 [error] 39055#100511: *6416645 limiting requests, excess: 0.712 by zone "crawler ...
show more
2024/08/02 21:39:46 [error] 39055#100511: *6416645 limiting requests, excess: 0.712 by zone "crawler", client: 2a03:2880:f806:9::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&action=showComment&commentUniqId=50f30cd45afde&seed=66300361dc212&fromWhere=showBookmarks HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-07-27 07:34:11
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:9:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 03:34:06.797166 2024] [security2:error] [pid 16327:tid 16327] [client 2a03:2880:f806:9:::35778] [client 2a03:2880:f806:9::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vangentholding.com|F|2"] [data ".yolasite.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vangentholding.com"] [uri "/tag/du-hoc-han-quoc-nganh-gi-tot/cohoiduhoc.yolasite.com"] [unique_id "ZqSi7kUI_ftEbMGeLKRKnwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-07-26 17:51:02
(2 years ago)
2a03:2880:f806:9:: - - [26/Jul/2024:17:50:54 +0000] "GET /generate/?exit_url=aWnHIPk3CltpuJZ29v42Hqa ...
show more
2a03:2880:f806:9:: - - [26/Jul/2024:17:50:54 +0000] "GET /generate/?exit_url=aWnHIPk3CltpuJZ29v42HqaSJXd1acIBaHR0cHM6Ly9hbmlkbC5kZGxzZXJ2ZXJ2MS5tZS5pbi9iZXRhL1BVVWhhZlBJUks2ck1tR1JFTGltc2VWdmtrcmczOFR2TXlSNDJFNE8zdzIyaEFpRDN4&identifier=esMo41lC3m0Wa3DYxqdPaVziKB7bj5OU HTTP/2.0" 500 2548 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack