๐บ๐ธ
TPI-Abuse
2025-01-15 17:36:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 15 12:36:04.342914 2025] [security2:error] [pid 409938:tid 409938] [client 2a0b:f4c2::8:14866] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benchmarkbcs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benchmarkbcs.com"] [uri "/daily.sql"] [unique_id "Z4fyBLQtToXDtw7n8FUZqAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-07 14:19:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 07 09:19:42.824648 2024] [security2:error] [pid 15383:tid 15383] [client 2a0b:f4c2::8:25580] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||veneerdent.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "veneerdent.com"] [uri "/ent.sql"] [unique_id "Z1RZfqq4VeU-gYpOxONb4gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 04:25:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 23:25:27.512160 2024] [security2:error] [pid 30786:tid 30786] [client 2a0b:f4c2::8:59684] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.handibets.com"] [uri "/.git/config"] [unique_id "Zz1kt-wlxZhIqSJY5W_tuQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 02:29:58
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 21:29:52.314378 2024] [security2:error] [pid 7241:tid 7241] [client 2a0b:f4c2::8:26142] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.grasspatchlal.com"] [uri "/.git/config"] [unique_id "Zz1JoDsph1IYu54bx6Ar4wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-09 11:30:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 09 07:30:28.997270 2024] [security2:error] [pid 13175:tid 13175] [client 2a0b:f4c2::8:59988] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||newcastle91.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "newcastle91.org"] [uri "/newcastl.sql"] [unique_id "ZwZpVJBOhXWJyGMl1ZbSHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-24 11:18:46
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 07:18:37.038415 2024] [security2:error] [pid 15693:tid 15693] [client 2a0b:f4c2::8:12970] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.phenoxcaribbean.com"] [uri "/.git/config"] [unique_id "ZvKgDShW8o8B2cT4GRTqSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MacLotsen
2024-08-28 17:47:33
(2 years ago)
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (SS; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.2.20"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-log
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-25 05:08:17
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 25 01:08:13.603426 2024] [security2:error] [pid 30184:tid 30184] [client 2a0b:f4c2::8:23794] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ultratecnologia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ultratecnologia.com"] [uri "/tratecnologia.sql"] [unique_id "Zsq8PdFtN8c4SDNoWnO1KQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 06:07:22
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 02:07:17.900788 2024] [security2:error] [pid 26060:tid 26060] [client 2a0b:f4c2::8:33550] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bendergloves.com"] [uri "/.git/config"] [unique_id "ZsGPlU2llNFThQH_XDDoQgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 03:08:33
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 23:08:26.529820 2024] [security2:error] [pid 32341:tid 32341] [client 2a0b:f4c2::8:64208] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.stat-alliance.com"] [uri "/.git/config"] [unique_id "ZsFlqj9cNCxdNxxUO0psFAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 10:02:29
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:234930) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 06:02:24.279532 2024] [security2:error] [pid 16167:tid 16167] [client 2a0b:f4c2::8:26618] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||art.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "art.mavikalem.org"] [uri "/en/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Zrc6sGbEVT1G0VwUXSvy5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-08 15:41:13
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 11:41:06.661944 2024] [security2:error] [pid 11200:tid 11200] [client 2a0b:f4c2::8:2608] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.consolidatedoperationsgroup.com"] [uri "/.git/config"] [unique_id "ZrTnEkE7CUkivWnN03w1WAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
OiledAmoeba
2024-08-06 21:04:07
(2 years ago)
2a0b:f4c2::8 - - [06/Aug/2024:23:03:48 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 25 ...
show more
2a0b:f4c2::8 - - [06/Aug/2024:23:03:48 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 258 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.776 "-"
2a0b:f4c2::8 - - [06/Aug/2024:23:03:53 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 256 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.750 "-"
2a0b:f4c2::8 - - [06/Aug/2024:23:04:04 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.622 "-"
2a0b:f4c2::8 - - [06/Aug/2024:23:04:06 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.455 "-"
2a0b:f4c2::8 - - [06/Aug/2024:23:04:07 +0200] "www.ruhnke.clou
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-08-06 04:00:54
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 06 00:00:49.705365 2024] [security2:error] [pid 2763729:tid 2763729] [client 2a0b:f4c2::8:64008] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.36sovereignchambers.com"] [uri "/.git/config"] [unique_id "ZrGf8bxZhmc7fsoY4F_CsgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-06 01:00:46
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::8 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 21:00:39.609211 2024] [security2:error] [pid 17427:tid 17427] [client 2a0b:f4c2::8:46416] [client 2a0b:f4c2::8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.495metro.com"] [uri "/.git/config"] [unique_id "ZrF1t6C8d8LTiJjD4mKr6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack