πΊπΈ
TPI-Abuse
2024-08-15 19:52:11
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 15:52:05.550125 2024] [security2:error] [pid 23446:tid 23446] [client 2a03:2880:f806:d:::38336] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richardpetersbooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richardpetersbooks.com"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "Zr5cZfHzXqR-GiGxwhQWmAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-15 09:46:29
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 05:46:22.478957 2024] [security2:error] [pid 8109:tid 8109] [client 2a03:2880:f806:d:::42700] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.artsy-style.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.artsy-style.com"] [uri "/ART/GLITZ/Thumbs.db"] [unique_id "Zr3ObqRbTWFhPdOkGgG_PQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-14 21:49:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 17:49:42.705171 2024] [security2:error] [pid 11892:tid 11892] [client 2a03:2880:f806:d:::48124] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pixelsbeach.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pixelsbeach.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zr0mdlgimGoRd18YIGqDoQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-13 14:42:34
(2 years ago)
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 10:42:30.147776 2024] [security2:error] [pid 29855:tid 29855] [client 2a03:2880:f806:d:::43614] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||depthsofsatan.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depthsofsatan.com"] [uri "/forum/"] [unique_id "Zrtw1uLrTTqHxOGr4Zb46AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-13 13:44:27
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 09:44:20.184302 2024] [security2:error] [pid 23229:tid 23229] [client 2a03:2880:f806:d:::41430] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realdoctorstories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realdoctorstories.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrtjNAM1C3d4SU8PQOFnPwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-13 09:11:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 05:11:12.962920 2024] [security2:error] [pid 16302:tid 16302] [client 2a03:2880:f806:d:::55448] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lzbvi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lzbvi.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrsjMPsT1-AaObARIbfQ_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-12 11:55:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 12 07:55:42.297613 2024] [security2:error] [pid 14171:tid 14171] [client 2a03:2880:f806:d:::45938] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.webflexdesign.co.uk|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.webflexdesign.co.uk"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zrn4Pk_QzQAgWfYbj9LZawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 03:41:41
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 23:41:37.574246 2024] [security2:error] [pid 28740:tid 28750] [client 2a03:2880:f806:d:::33980] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/newsletters/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/newsletters/%url%"] [unique_id "ZrWP8V33jwYa2g_3NZ_sMAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-07 21:42:06
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 17:42:00.907621 2024] [security2:error] [pid 16657:tid 16657] [client 2a03:2880:f806:d:::39068] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.scoutinsignia.com|F|2"] [data ".ebay.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.scoutinsignia.com"] [uri "/www.ebay.com"] [unique_id "ZrPqKI7P4-Mzi1ktUVpVlQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2024-08-03 03:20:04
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2024-08-03 03:12:38
(2 years ago)
2024/08/03 05:12:37 [error] 83839#612862: *6571939 limiting requests, excess: 0.241 by zone "crawler ...
show more
2024/08/03 05:12:37 [error] 83839#612862: *6571939 limiting requests, excess: 0.241 by zone "crawler", client: 2a03:2880:f806:d::, server: crxforum.ksol.io, request: "GET /showRecAnswers.php?topicId=565&commentUniqId=58e10ba17382b&seed=663051260453a HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
π©πͺ
ghostwarriors
2024-07-24 08:20:08
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2024-07-24 08:08:57
(2 years ago)
2024/07/24 10:08:56 [error] 25223#101024: *1725468 limiting requests, excess: 0.006 by zone "crawler ...
show more
2024/07/24 10:08:56 [error] 25223#101024: *1725468 limiting requests, excess: 0.006 by zone "crawler", client: 2a03:2880:f806:d::, server: git.ksol.io, request: "GET /karolyi/xapian-haystack/src/commit/af9ca09f27d77c494a0b7160bf564cba9bd3c31d/tests/xapian_tests/tests/xapian_backend.py HTTP/2.0", host: "git.ksol.io"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-07-10 23:30:16
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 10 19:30:09.152663 2024] [security2:error] [pid 15681] [client 2a03:2880:f806:d:::51552] [client 2a03:2880:f806:d::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soudertonbigred.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soudertonbigred.org"] [uri "/wp-json/wp/v2/users/6"] [unique_id "Zo8Zge5_RtI-w3GHTnvZEAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack