๐บ๐ธ
zorrigas
2025-09-17 09:05:54
(11 months ago)
(mod_security) mod_security (id:243930) triggered by 45.151.62.109 (RU/Russia/37481.ip-ptr.tech): 5 ...
show more
(mod_security) mod_security (id:243930) triggered by 45.151.62.109 (RU/Russia/37481.ip-ptr.tech): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-22 02:53:31
(1 year ago)
[Tue Jul 22 09:52:19.734410 2025] [security2:error] [pid 317288:tid 139733917222592] [client 45.151. ...
show more
[Tue Jul 22 09:52:19.734410 2025] [security2:error] [pid 317288:tid 139733917222592] [client 45.151.62.109:14145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "session" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: session found within REQUEST_FILENAME: /session_login.cgi request_line = POST /session_login.cgi HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/session_login.cgi"] [unique_id "aH784xJM7rG2smogjW1HEQAAAJc"], referer https://staklim-jatim.bmkg.go.id [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[317338] [uqY/rvtVqtM] [aH784xJM7rG2smogjW1HEQAAAJc] keep_alive=[0] [2025-07-22 09:52:19.734422] [R:aH784xJM7rG2smogjW1HEQAAAJc] UA:'Mozilla/5.0 (X11; Linux i686; rv:128.0) Gecko/20100101 Firefox/128.0' Host:'staklim-jatim.bmkg.go.id' COOKIE:'redirect=1; testing=1'
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-21 21:37:48
(1 year ago)
[Tue Jul 22 04:37:02.672227 2025] [security2:error] [pid 150813:tid 139734579918528] [client 45.151. ...
show more
[Tue Jul 22 04:37:02.672227 2025] [security2:error] [pid 150813:tid 139734579918528] [client 45.151.62.109:32011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/upload.php" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /upload.php found within REQUEST_FILENAME: /php/upload.php request_line = POST /php/upload.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/php/upload.php"] [unique_id "aH6y_h7u94PtNF0cBhR43gAAAE8"], referer https://staklim-jatim.bmkg.go.id [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[150855] [y2G1RveS6ck] [aH6y_h7u94PtNF0cBhR43gAAAE8] keep_alive=[0] [2025-07-22 04:37:02.672231] [R:aH6y_h7u94PtNF0cBhR43gAAAE8] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.81 Safari/537.36' Host:'staklim-ja
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-21 16:32:49
(1 year ago)
Citrix SD-WAN Center Unauthenticated Command Injection Vulnerability(56029)
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-20 19:49:51
(1 year ago)
[Mon Jul 21 02:49:51.170912 2025] [security2:error] [pid 135117:tid 140080719046336] [client 45.151. ...
show more
[Mon Jul 21 02:49:51.170912 2025] [security2:error] [pid 135117:tid 140080719046336] [client 45.151.62.109:31847] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wls-wsat" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /wls-wsat found within REQUEST_FILENAME: /wls-wsat/RegistrationRequesterPortType request_line = POST /wls-wsat/RegistrationRequesterPortType HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/wls-wsat/RegistrationRequesterPortType"] [unique_id "aH1IX-mDFHhRcXkWVz1mlgAAAFA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[135160] [cyaGqaEC9m0] [aH1IX-mDFHhRcXkWVz1mlgAAAFA] keep_alive=[0] [2025-07-21 02:49:51.170917] [R:aH1IX-mDFHhRcXkWVz1mlgAAAFA] UA:'Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36' Host:'
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-20 17:03:15
(1 year ago)
phpMyadmin Scripts Deserialization Vulnerability(59315)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-20 16:45:55
(1 year ago)
Weaver Ecology-OA Remote Code Execution Vulnerability(56983)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-20 16:28:41
(1 year ago)
Bash Remote Code Execution Vulnerability(36729)
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-20 08:07:43
(1 year ago)
[Sun Jul 20 15:02:14.222755 2025] [security2:error] [pid 48386:tid 140551496120000] [client 45.151.6 ...
show more
[Sun Jul 20 15:02:14.222755 2025] [security2:error] [pid 48386:tid 140551496120000] [client 45.151.62.109:14021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/login" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /login found within REQUEST_FILENAME: /login.action request_line = GET /login.action?redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/login.action"] [unique_id "aHyiho7uA
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-20 02:52:31
(1 year ago)
[Sun Jul 20 09:49:27.246736 2025] [security2:error] [pid 794985:tid 139892579362496] [client 45.151. ...
show more
[Sun Jul 20 09:49:27.246736 2025] [security2:error] [pid 794985:tid 139892579362496] [client 45.151.62.109:5941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/user.action" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /user.action found within REQUEST_FILENAME: /user.action request_line = POST /user.action HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/user.action"] [unique_id "aHxZN02NeSWRjBA2CQMoZQAAAAo"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[795022] [blhKaBN3UIE] [aHxZN02NeSWRjBA2CQMoZQAAAAo] keep_alive=[0] [2025-07-20 09:49:27.246742] [R:aHxZN02NeSWRjBA2CQMoZQAAAAo] UA:'Mozilla/5.0 (SS; Linux i686; rv:125.0) Gecko/20100101 Firefox/125.0' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'*/*' Accept-Encoding:'gzip Accept-Language:'en
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-19 20:16:14
(1 year ago)
Shellshock attack attempt-95
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-19 17:07:13
(1 year ago)
PHP CGI Query String Parameter Handling Information Disclosure Vulnerability(34804)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-19 16:48:11
(1 year ago)
Apache Struts2 Redirect/Action Method Remote Code Execution Vulnerability(56944)
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-19 16:28:11
(1 year ago)
Bash Remote Code Execution Vulnerability(36729)
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-17 04:32:52
(1 year ago)
[Thu Jul 17 11:30:03.978572 2025] [security2:error] [pid 139982:tid 140535104771776] [client 45.151. ...
show more
[Thu Jul 17 11:30:03.978572 2025] [security2:error] [pid 139982:tid 140535104771776] [client 45.151.62.109:32541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/webshell" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /webshell found within REQUEST_FILENAME: /manage/webshell/u request_line = GET /manage/webshell/u?s=5&w=218&h=15&k=%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a&l=62&_=5621298674064 HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/manage/webshell/u"] [unique_id "aHh8Syz3hbZX6TZdoNlzBQAAAI0"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[140022] [8xCGdhhxK1M] [aHh8Syz3hbZX6TZdoNlzBQAAAI0] keep_alive=[0] [2025-07-17 11:30:03.978579] [R:aHh8Syz3hbZX6TZdoNlzBQAAAI0] UA:'Mozilla/5.0 (Windows; U; Windows NT 6.1; sv-SE) AppleWebKit/533.19.4 (KH
...
show less
Hacking
Web App Attack