πΊπΈ
TPI-Abuse
2024-08-20 12:25:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 20 08:25:15.667023 2024] [security2:error] [pid 23185:tid 23185] [client 2a03:2880:f806:e:::36436] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ncrcs.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ncrcs.org"] [uri "/beginners/[email protected] "] [unique_id "ZsSLK2YzNOhCCfGX1oVf1AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-20 06:25:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 20 02:25:39.469483 2024] [security2:error] [pid 29776:tid 29776] [client 2a03:2880:f806:e:::34624] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chrisbilder.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chrisbilder.com"] [uri "/stat873/data_sets/WHEAT.DAT"] [unique_id "ZsQ243DR9dq4w5d3LWr9hQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-17 17:21:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 13:21:43.205455 2024] [security2:error] [pid 10477:tid 10477] [client 2a03:2880:f806:e:::36382] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nwuoregon.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nwuoregon.org"] [uri "/wp-json/wp/v2/users/7"] [unique_id "ZsDcJ5bIp25bF_j5dEEzQgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-17 03:45:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 23:44:59.909974 2024] [security2:error] [pid 13324:tid 13324] [client 2a03:2880:f806:e:::39004] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.inverzona.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZsAcuw24tgt7M6BZh7NurwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-16 18:55:59
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 14:55:52.235938 2024] [security2:error] [pid 8667:tid 8667] [client 2a03:2880:f806:e:::36862] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||briannalls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "briannalls.com"] [uri "/index.php/wp-json/wp/v2/users/1"] [unique_id "Zr-guMp91ZiSS4nnfBxNZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-16 12:17:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 08:17:19.464282 2024] [security2:error] [pid 4610:tid 4610] [client 2a03:2880:f806:e:::33016] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.doctorc.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.doctorc.net"] [uri "/Labs/Lab4/NOTES/FINDER.DAT"] [unique_id "Zr9DT0CzKGAIIkc9UghO8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-15 13:04:05
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 09:03:58.593405 2024] [security2:error] [pid 18278:tid 18278] [client 2a03:2880:f806:e:::46374] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pointillistic.com|F|2"] [data ".bravecoolworld.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pointillistic.com"] [uri "/vmps-audio/www.bravecoolworld.com"] [unique_id "Zr38vswGsy4hr8fjSET-fgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-15 00:13:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 20:13:25.374296 2024] [security2:error] [pid 16119:tid 16119] [client 2a03:2880:f806:e:::57180] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pointandshootfilm.com|F|2"] [data ".facebook.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pointandshootfilm.com"] [uri "/www.facebook.com"] [unique_id "Zr1IJbxaLy_zxFC_bf3dKgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-14 02:59:37
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 22:59:34.162717 2024] [security2:error] [pid 14113:tid 14113] [client 2a03:2880:f806:e:::35562] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.campos.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.campos.tv"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrwdltdyxIAEHP1PYM07swAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-14 00:47:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 13 20:47:19.755922 2024] [security2:error] [pid 1043:tid 1043] [client 2a03:2880:f806:e:::56202] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kingstoneproperties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kingstoneproperties.com"] [uri "/[email protected] "] [unique_id "Zrv-l229c6IibCbY9m8LTgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-12 18:58:49
(2 years ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 12 14:58:45.677063 2024] [security2:error] [pid 2429570:tid 2429570] [client 2a03:2880:f806:e:::40126] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||www.cffragrances.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cffragrances.iee-usa.com"] [uri "/wp-includes/js/tinymce/themes/advanced/js/"] [unique_id "ZrpbZRPlEAbrDV1aLf8w-QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-11 23:28:53
(2 years ago)
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211180) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 19:28:48.120372 2024] [security2:error] [pid 3174:tid 3174] [client 2a03:2880:f806:e:::38186] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||depthsofsatan.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depthsofsatan.com"] [uri "/forum/index.php"] [unique_id "ZrlJMOClPoal6ipaBv_aQQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-10 16:13:48
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 12:13:42.140154 2024] [security2:error] [pid 6333:tid 6333] [client 2a03:2880:f806:e:::51426] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.empoweryourcents.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.empoweryourcents.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZreRth1GRkDpV2atzAuOPAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 22:25:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 18:25:19.737002 2024] [security2:error] [pid 20632:tid 20632] [client 2a03:2880:f806:e:::35786] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "ZraXT67kc1KoYMy1sAxipgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-09 22:04:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 18:04:02.361490 2024] [security2:error] [pid 3920:tid 3920] [client 2a03:2880:f806:e:::55154] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.goldcountrygermanamericanclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.goldcountrygermanamericanclub.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZraSUp8YhWjMxYQWYxujrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack