hermawan
|
|
[Tue Jan 21 21:05:48.993807 2025] [security2:error] [pid 723830:tid 132970842502848] [client 36.110. ... show more[Tue Jan 21 21:05:48.993807 2025] [security2:error] [pid 723830:tid 132970842502848] [client 36.110.131.185:51787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "59"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z4-pvPpfOzTUPxVaZ6p6BQAALCk"], referer https://staklim-jatim.bmkg.go.id/index.php/monitoring-hari-tanpa-hujan-berturut-turut/3921-monitoring-hari-tanpa-hujan-berturut-turut-interpolasi/monitoring-hari-tanpa-hujan-berturut-turut-interpolasi-di-provinsi-jawa-timur/monitoring-hari-tanpa-hujan-
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Mon Jan 20 10:28:49.577085 2025] [security2:error] [pid 41599:tid 126836319164096] [client 36.110.1 ... show more[Mon Jan 20 10:28:49.577085 2025] [security2:error] [pid 41599:tid 126836319164096] [client 36.110.131.185:51772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "59"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z43C8ay3--Gz0OBLYsnF_QABNQU"], referer https://staklim-malang.info/index.php/profil/arsip-artikel?catid=476&id=996%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-17-23-mei-2016&start=30 [staklim-malang.info] [staklim-malang.info] top=[41605] [2H/V2zJZo5E] [
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Wed Jan 15 00:38:47.234234 2025] [security2:error] [pid 88917:tid 137708160333504] [client 36.110.1 ... show more[Wed Jan 15 00:38:47.234234 2025] [security2:error] [pid 88917:tid 137708160333504] [client 36.110.131.185:38412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "59"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z4ahJ31lTxcwz5ToI4xrtgAB2kA"], referer https://staklim-jatim.bmkg.go.id/index.php/prakiraan-iklim/prakiraan-dasarian/prakiraan-dasarian-daerah-potensi-banjir/555560978-prakiraan-dasarian-daerah-potensi-banjir-di-provinsi-jawa-timur-untuk-bulan-juni-dasarian-ii-tahun-2024-tanggal-11-20-juni-2
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Mon Jan 13 02:10:47.484729 2025] [security2:error] [pid 125644:tid 139602120599232] [client 36.110. ... show more[Mon Jan 13 02:10:47.484729 2025] [security2:error] [pid 125644:tid 139602120599232] [client 36.110.131.185:43941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "57"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z4QTt6q6yrM5fHv742vj1wAAux4"], referer https://staklim-malang.info/index.php/profil/meteorologi/list-all-categories/3907-klimatologi/analisis-klimatologi/analisis-dasarian/distribusi-curah-hujan-dasarian-propinsi-jawa-timur/distribusi-curah-hujan-dasarian-propinsi-jawa-timur-tahun-20
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sat Jan 11 23:38:14.082628 2025] [security2:error] [pid 29686:tid 124634848503488] [client 36.110.1 ... show more[Sat Jan 11 23:38:14.082628 2025] [security2:error] [pid 29686:tid 124634848503488] [client 36.110.131.185:46586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "57"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z4KedtZKUA5PFJKH6cUz1QAB-w4"], referer https://staklim-jatim.bmkg.go.id/index.php/analisis-bulanan/4041-analisis-distribusi-hujan/analisis-distribusi-curah-hujan/analisis-distribusi-curah-hujan-jawa-timur-bulanan/analisis-bulanan-distribusi-curah-hujan-tahun-2020/555558051-analisis-bulanan-d
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Fri Jan 10 14:17:33.745793 2025] [security2:error] [pid 63875:tid 125614717904576] [client 36.110.1 ... show more[Fri Jan 10 14:17:33.745793 2025] [security2:error] [pid 63875:tid 125614717904576] [client 36.110.131.185:23559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "64"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z4DJjRWmpr8kJkaiu2oj-AAArWQ"], referer https://staklim-malang.info/index.php/profil/arsip-artikel?catid=488&id=819%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-1-7-desember-2015 [staklim-malang.info] [staklim-malang.info] top=[64669] [Euhx43yFqBs] [Z4DJjR
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Fri Jan 03 23:41:55.300664 2025] [security2:error] [pid 76893:tid 136438693238464] [client 36.110.1 ... show more[Fri Jan 03 23:41:55.300664 2025] [security2:error] [pid 76893:tid 136438693238464] [client 36.110.131.185:46263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "64"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z3gTU-MlycQ-gcx_SatVkAACDxE"], referer https://staklim-jatim.bmkg.go.id/index.php/profil/meteorologi/list-of-all-tags/infografis-bulanan-tahun-2018 [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[76911] [JH3c9EcZ/X8] [Z3gTU-MlycQ-gcx_SatVkAACDxE] keep_alive=[1] [2025-01-03 23:41:55
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Mon Dec 30 19:26:45.103220 2024] [security2:error] [pid 177430:tid 138939367773888] [client 36.110. ... show more[Mon Dec 30 19:26:45.103220 2024] [security2:error] [pid 177430:tid 138939367773888] [client 36.110.131.185:55543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z3KRhYMLtBKfdAptnUg-hQAGKxs"], referer https://staklim-malang.info/index.php/profil/meteorologi/list-all-categories/4217-klimatologi/prakiraan-klimatologi/prakiraan-dasarian/prakiraan-curah-hujan-dasarian/prakiraan-probabilistik-curah-hujan-dasarian/prakiraan-probabilistik-curah-hujan
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sat Dec 28 15:41:28.407103 2024] [security2:error] [pid 40981:tid 133234795243200] [client 36.110.1 ... show more[Sat Dec 28 15:41:28.407103 2024] [security2:error] [pid 40981:tid 133234795243200] [client 36.110.131.185:63500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z2-5uIQAiz7VO43nu7gGQgABLEw"], referer https://staklim-malang.info/index.php/profil/meteorologi/list-of-all-tags/analisis-distribusi-curah-hujan-malang-bulanan-tahun-2011 [staklim-malang.info] [staklim-malang.info] top=[41058] [JIP/irhnFZQ] [Z2-5uIQAiz7VO43nu7gGQgABLEw] keep_alive=[1] [2024-12-28
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Fri Dec 27 03:47:30.020759 2024] [security2:error] [pid 638180:tid 138323391452864] [client 36.110. ... show more[Fri Dec 27 03:47:30.020759 2024] [security2:error] [pid 638180:tid 138323391452864] [client 36.110.131.185:50059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z23A4qbWHt8_5ZXDFe1dIgADFDQ"], referer https://staklim-malang.info/index.php/profil/arsip-artikel?catid=488&id=1274%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-14-19-desember-2016&start=80 [staklim-malang.info] [staklim-malang.info] top=[638233] [LKNjdLp
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sat Dec 21 05:17:08.445281 2024] [security2:error] [pid 182078:tid 125554810316480] [client 36.110. ... show more[Sat Dec 21 05:17:08.445281 2024] [security2:error] [pid 182078:tid 125554810316480] [client 36.110.131.185:46191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /OneSignalSDKWorker.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/OneSignalSDKWorker.js"] [unique_id "Z2Xs5NBUFy5hfX801ComWQACaxk"], referer https://staklim-jatim.bmkg.go.id/index.php/profil/meteorologi/list-all-categories/4076-klimatologi/prakiraan-klimatologi/prakiraan-dasarian/prakiraan-dasarian-daerah-potensi-banjir/prakiraan-dasarian-daerah-potensi-banjir-di-provinsi-jawa-timur/prakiraa
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Sat Dec 07 15:20:58.286407 2024] [security2:error] [pid 196765:tid 130538775983808] [client 36.110. ... show more[Sat Dec 07 15:20:58.286407 2024] [security2:error] [pid 196765:tid 130538775983808] [client 36.110.131.185:53719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z1QFarS0iWiupf28UTZTkgAClgo"], referer https://staklim-malang.info/index.php/prakiraan-iklim/prakiraan-musim/prakiraan-musim-kemarau/prakiraan-puncak-musim-kemarau-zona-musim-di-provinsi-jawa-timur [staklim-malang.info] [staklim-malang.info] top=[196776] [4pabzyHcDgk] [Z1QFarS0iWiupf2
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Mon Dec 02 03:52:39.097550 2024] [security2:error] [pid 510316:tid 128511328097984] [client 36.110. ... show more[Mon Dec 02 03:52:39.097550 2024] [security2:error] [pid 510316:tid 128511328097984] [client 36.110.131.185:8717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z0zMl4tbF3HZrdbc_h6xsAAB0QM"], referer https://staklim-malang.info/index.php/profil/arsip-artikel?catid=480&id=766%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-20-oktober-26-oktober-2015&start=20 [staklim-malang.info] [staklim-malang.info] top=[510320] [Mm
... show less
|
Hacking
Web App Attack
|
|
hermawan
|
|
[Tue Nov 26 15:35:06.553619 2024] [security2:error] [pid 554858:tid 125778238764736] [client 36.110. ... show more[Tue Nov 26 15:35:06.553619 2024] [security2:error] [pid 554858:tid 125778238764736] [client 36.110.131.185:53698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Head" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Head found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.5938.60 Safari/537.36 request_line = GET /TableFilter/system-v167.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/TableFilter/system-v167.css"] [unique_id "Z0WIOm3jn1xtcGXQfRQBhgACqiA"], referer https://staklim-malang.info/index.php/prakiraan-bulanan/4262-prakiraan-bulanan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/prakiraan-bulanan-sifat-hujan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/555561193-prakiraan-bulanan-sifat-hujan-di-ka
... show less
|
Hacking
Web App Attack
|
|
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|