๐บ๐ธ
TPI-Abuse
2024-08-09 22:04:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 18:04:02.361490 2024] [security2:error] [pid 3920:tid 3920] [client 2a03:2880:f806:e:::55154] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.goldcountrygermanamericanclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.goldcountrygermanamericanclub.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZraSUp8YhWjMxYQWYxujrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 20:19:32
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 16:19:25.096590 2024] [security2:error] [pid 22267:tid 22267] [client 2a03:2880:f806:e:::60254] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kandocopies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kandocopies.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrZ5zdt0pVOCgn_xIQ0IFwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 03:33:15
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 23:33:06.447199 2024] [security2:error] [pid 28078:tid 28143] [client 2a03:2880:f806:e:::41208] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gabegabel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gabegabel.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrWN8q1W6GolCdelIS5WugAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 02:07:00
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 22:06:52.410351 2024] [security2:error] [pid 28716:tid 28716] [client 2a03:2880:f806:e:::60082] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.buanamegah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.buanamegah.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrV5vDGD76hChfZqV-zYfAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 05:30:44
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 01:30:38.547761 2024] [security2:error] [pid 734274:tid 734274] [client 2a03:2880:f806:e:::49348] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dailybeautysupply.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dailybeautysupply.com"] [uri "/store/c2/Hair_Care.html/&sa=U&ved=2ahUKEwiA89iT0uzzAhXVbCsKHbeFA2IQFnoECBsQAg&usg=AOvVaw1lKcn-WLWFamr6RcENDbdH/magmi/conf/magmi.ini"] [unique_id "ZrRX_le3Wg066VTf-xGDGgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-05 21:35:53
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 17:35:47.408731 2024] [security2:error] [pid 7286:tid 7286] [client 2a03:2880:f806:e:::58056] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||timbertoysbt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "timbertoysbt.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZrFFs-DydcoAwQSZmA7X2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-03 02:23:36
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 02 22:23:31.012056 2024] [security2:error] [pid 15150:tid 15150] [client 2a03:2880:f806:e:::53398] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Zq2Uo2MkK6gW5JLMiWIBrwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-08-02 19:02:55
(2 years ago)
2024/08/02 21:02:54 [error] 39055#100511: *6403231 limiting requests, excess: 0.252 by zone "crawler ...
show more
2024/08/02 21:02:54 [error] 39055#100511: *6403231 limiting requests, excess: 0.252 by zone "crawler", client: 2a03:2880:f806:e::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&action=showComment&commentUniqId=5888c904a4515&seed=66359609c7988 HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-28 03:01:01
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 23:00:55.284406 2024] [security2:error] [pid 9474:tid 9474] [client 2a03:2880:f806:e:::54870] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.foe4408.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.foe4408.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZqW0Z38D_F3PxUw7F0NzuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-25 17:41:52
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 25 13:41:49.790128 2024] [security2:error] [pid 9194:tid 9194] [client 2a03:2880:f806:e:::38496] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vangentholding.com|F|2"] [data ".yolasite.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vangentholding.com"] [uri "/tag/panmunjeom-flag/cohoiduhoc.yolasite.com"] [unique_id "ZqKOXRy18H0nsiz5A8QjkAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-07-24 16:20:07
(2 years ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2024-07-24 15:56:25
(2 years ago)
2024/07/24 17:56:24 [error] 25223#101024: *1861705 limiting requests, excess: 0.480 by zone "crawler ...
show more
2024/07/24 17:56:24 [error] 25223#101024: *1861705 limiting requests, excess: 0.480 by zone "crawler", client: 2a03:2880:f806:e::, server: crxforum.ksol.io, request: "GET /showTopic.php?topicId=565&action=showComment&commentUniqId=50f2e619d31bd&seed=668fc6b37478c HTTP/2.0", host: "crxforum.ksol.io"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-23 11:35:51
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 23 07:35:43.582457 2024] [security2:error] [pid 17717:tid 17717] [client 2a03:2880:f806:e:::47938] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.circulodesonido.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.circulodesonido.org"] [uri "/contactos/europa/espana/[email protected] "] [unique_id "Zp-Vj-9tmkX4GcLp_RfnCwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-18 17:51:06
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 18 13:51:02.361834 2024] [security2:error] [pid 25327:tid 25327] [client 2a03:2880:f806:e:::59360] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sandiegoautostarsmog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sandiegoautostarsmog.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZplWBq6deS1Y0oMzAwx89wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-17 03:44:56
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 16 23:44:50.871744 2024] [security2:error] [pid 6269] [client 2a03:2880:f806:e:::40224] [client 2a03:2880:f806:e::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".williamfitzsimmons.tix.musictoday.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0410-william-fitzsimmons-spring-tour-update/www.williamfitzsimmons.tix.musictoday.com"] [unique_id "Zpc-MuxkOiEkTwRWifi7uQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack