๐บ๐ธ
TPI-Abuse
2024-08-18 14:46:12
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 10:46:09.441718 2024] [security2:error] [pid 28909:tid 28909] [client 2a03:2880:f806:b:::50536] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZsIJMXoBKclfSunqlKnWNQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 02:44:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 22:44:26.209472 2024] [security2:error] [pid 3908607:tid 3908607] [client 2a03:2880:f806:b:::54328] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "ZsFgCj8dPab8Vdt4ElXXGwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 19:42:31
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 15:42:28.013476 2024] [security2:error] [pid 3848670:tid 3848670] [client 2a03:2880:f806:b:::45184] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lasertherapyoc.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zr-rpJwcLm29QhTDipZbDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 11:03:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 07:03:29.516656 2024] [security2:error] [pid 23217:tid 23217] [client 2a03:2880:f806:b:::41212] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".thehowardtheatre.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0328-william-adds-chattanooga-date-uscan-tour/www.thehowardtheatre.com"] [unique_id "Zr8yAWpQfIBAeteSB6QEXwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 08:45:19
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 04:45:15.386476 2024] [security2:error] [pid 17225:tid 17225] [client 2a03:2880:f806:b:::41500] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "Zr8Rm4ktrVQxTgkkfJh3yAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 22:34:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 18:34:45.637766 2024] [security2:error] [pid 25053:tid 25053] [client 2a03:2880:f806:b:::42888] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kporterdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kporterdesign.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zr6ChTl6MaHK3Xe1xXKr3gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 10:23:04
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 06:22:56.654185 2024] [security2:error] [pid 16608:tid 16608] [client 2a03:2880:f806:b:::49440] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.highgroundsconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.highgroundsconsulting.com"] [uri "/Introduction/wp-json/wp/v2/users/1"] [unique_id "Zr3XAI_qEhN_XfLvcaiU0gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 01:25:16
(2 years ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 21:25:10.428267 2024] [security2:error] [pid 31444:tid 31444] [client 2a03:2880:f806:b:::35084] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||cerrovictoria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cerrovictoria.com"] [uri "/housingdeautor.com/WordPress/wp-includes/js/mediaelement/"] [unique_id "Zr1Y9qW0YzYgw9N3aZDHmAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 18:35:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 14:35:39.513698 2024] [security2:error] [pid 526687:tid 526687] [client 2a03:2880:f806:b:::36342] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dailybeautysupply.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dailybeautysupply.com"] [uri "/store/c2/Hair_Care.html/&sa=U&ved=2ahUKEwiA89iT0uzzAhXVbCsKHbeFA2IQFnoECBsQAg&usg=AOvVaw1lKcn-WLWFamr6RcENDbdH/magmi/conf/magmi.ini"] [unique_id "Zrune3MakJLRKKtxLHAubAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 16:51:24
(2 years ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 12:51:19.095747 2024] [security2:error] [pid 3555827:tid 3555827] [client 2a03:2880:f806:b:::39412] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||www.cffragrances.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cffragrances.iee-usa.com"] [uri "/wp-includes/js/tinymce/themes/advanced/skins/"] [unique_id "ZruPB89CBj8Nmju9ilxQXAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 01:44:52
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 12 21:44:48.192596 2024] [security2:error] [pid 2878:tid 2878] [client 2a03:2880:f806:b:::56134] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indyham.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indyham.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zrq6kPWz5aRhiYdLib1CVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-13 00:18:12
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 12 20:18:08.739184 2024] [security2:error] [pid 1455:tid 1455] [client 2a03:2880:f806:b:::49402] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctorc.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctorc.net"] [uri "/Labs/Lab13/FINDER.DAT"] [unique_id "ZrqmQMvI4hlfpXr4Zq4o2wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-11 02:10:51
(2 years ago)
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 22:10:47.801414 2024] [security2:error] [pid 18604:tid 18604] [client 2a03:2880:f806:b:::42928] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||depthsofsatan.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depthsofsatan.com"] [uri "/forum/"] [unique_id "Zrgdp0fHKLfg0uGU2qF24gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 18:12:43
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 14:11:03.995332 2024] [security2:error] [pid 3506:tid 3539] [client 2a03:2880:f806:b:::47022] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/buy/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/buy/%url%"] [unique_id "ZrZbtyVPQ-pjhZQ6lUEujQAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 16:34:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 12:34:05.097409 2024] [security2:error] [pid 10676:tid 10676] [client 2a03:2880:f806:b:::55022] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "ZrTzfbAsRHETgUFFcr18mgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack