๐ฉ๐ช
conseilgouz
2024-12-03 08:03:49
(1 year ago)
coe-12 : Block return, carriage return, ... characters=>/index.php?option=com_content&view=artic ...
show more
coe-12 : Block return, carriage return, ... characters=>/index.php?option=com_content&view=article&id=153&Itemid=888'(')
show less
Hacking
Anonymous
2024-12-01 13:52:00
(1 year ago)
MALWARE-OTHER Php.Webshell.AK74
Web App Attack
๐ช๐ธ
el-brujo
2024-12-01 05:42:52
(1 year ago)
01/Dec/2024:06:42:52.522056 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Dec/2024:06:42:52.522056 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 45.32.219.178] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "957"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/plain|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "ns2.elhacker.net"] [uri "/timofonica/manuales/hackeando_con_google.pdf'"] [unique_id "Z0v3XF_4hCe7c4Zrg82PcAADVCY"]
...
show less
Hacking
Web App Attack
๐ต๐ฑ
nfsec.pl
2024-11-30 18:17:58
(1 year ago)
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.bak HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Wi ...
show more
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.bak HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.dev HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.prod HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.prod.local HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
45.32.219.178 - - [30/Nov/2024:19:17:58 +0100] "GET /.env.stage HTTP/1.1" 403 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-30 16:59:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.32.219.178 (45.32.219.178.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 45.32.219.178 (45.32.219.178.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 30 11:59:32.232169 2024] [security2:error] [pid 18508:tid 18508] [client 45.32.219.178:56537] [client 45.32.219.178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gsf-soft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gsf-soft.com"] [uri "/Products/DYL2CBL.html/mailto:[email protected] "] [unique_id "Z0tEdFcCxkotoPN9NIL2nwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-11-29 11:08:46
(1 year ago)
SQL injection attempt.-113
Web App Attack
๐บ๐ธ
SiliSoftware
2024-11-28 19:14:32
(1 year ago)
/'
Web App Attack
๐ช๐ธ
Reinhard
2024-11-28 19:09:00
(1 year ago)
Msg from error-handling: Error:/widwsisw/i/i0004en.php'. Body:Thu, 28 Nov 2024 20:09:31 +0100, ...
show more
Msg from error-handling: Error:/widwsisw/i/i0004en.php'. Body:Thu, 28 Nov 2024 20:09:31 +0100, IP-Addr:45.32.219.178, Host:45.32.219.178.vultrusercontent.com
show less
Hacking
SQL Injection
Brute-Force
Web App Attack
๐ณ๐ฑ
exxos
2024-11-28 13:03:37
(1 year ago)
Traversal attacks
Hacking
๐ฉ๐ช
bsoft.de
2024-11-22 20:40:00
(1 year ago)
Web App Attack
Web App Attack
Anonymous
2024-11-22 20:18:15
(1 year ago)
fail2ban_mm apache-modsecurity [msg "Multiple URL Encoding Detected"] [uri "/cgi-bin/new.cgi"]
Web App Attack
๐ซ๐ท
himanshu LNU
2024-11-19 13:58:01
(1 year ago)
Domain : globalgetconnect.com
Rule : DangerQueryString
2024-11-19 13:57:09 ***hidden-privacy*** GET ...
show more
Domain : globalgetconnect.com
Rule : DangerQueryString
2024-11-19 13:57:09 ***hidden-privacy*** GET /client_detail.aspx cid=32029
show less
Web App Attack
๐น๐ญ
MWA SOC
2024-11-19 11:21:00
(1 year ago)
Hacking
๐บ๐ธ
TPI-Abuse
2024-11-19 11:13:44
(1 year ago)
(mod_security) mod_security (id:210580) triggered by 45.32.219.178 (45.32.219.178.vultrusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 45.32.219.178 (45.32.219.178.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 06:13:37.914945 2024] [security2:error] [pid 16265:tid 16265] [client 45.32.219.178:62991] [client 45.32.219.178] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:type. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.shukrisharawico.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:type: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.shukrisharawico.com"] [uri "/module.php"] [unique_id "Zzxy4TpArd_jQ4gEo04MuAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2024-11-19 09:05:25
(1 year ago)
Traversal attacks
Hacking