|
Anonymous
|
|
alibaba cloud ddos like web scan
|
Bad Web Bot
|
|
|
Anonymous
|
|
alibaba cloud ddos like web scan
|
Bad Web Bot
|
|
|
Anonymous
|
|
alibaba cloud ddos like web scan
|
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211190) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream ...
show more
(mod_security) mod_security (id:211190) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 16:23:19.812612 2024] [security2:error] [pid 22622:tid 22634] [client 45.61.100.82:60273] [client 45.61.100.82] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||autodiscover.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_ccnewsletter&controller=../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kettlehill.net"] [uri "/index.php"] [unique_id "ZqVXNz1IczihROHRlilqSwAAAMk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Unauthorized login attempts [ accesslogs]
|
Brute-Force
|
|
|
Anonymous
|
|
Common attack or app scan event detected and blocked
|
Port Scan
Hacking
Web App Attack
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Unauthorized login attempts [ accesslogs]
|
Brute-Force
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Unauthorized login attempts [ BI-16635]
|
Brute-Force
|
|
|
πͺπΈ
10dencehispahard SL
|
|
WP scan
|
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 13 18:55:07.338306 2024] [security2:error] [pid 13161:tid 46964668376832] [client 45.61.100.82:53093] [client 45.61.100.82] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.kettlehill.net"] [uri "/wp-config.php.orig"] [unique_id "ZcwBW6emS_vM90JN0V6xSwAAAck"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 25 13:44:02.371486 2024] [security2:error] [pid 21707] [client 45.61.100.82:58073] [client 45.61.100.82] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.stdavids-media.com"] [uri "/wp-config.php.bak"] [unique_id "ZbKr8mS7BcV9pHhkbhPdGAAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:212620) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream ...
show more
(mod_security) mod_security (id:212620) triggered by 45.61.100.82 (ip-45-61-100-82.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 28 18:27:43.044799 2023] [security2:error] [pid 23446:tid 47740344145664] [client 45.61.100.82:46027] [client 45.61.100.82] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /oauth/idp/logout?post_logout_redirect_uri=<script>console.log(`xss`)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kettlehill.com"] [uri "/oauth/idp/logout"] [unique_id "ZWZ3b9yBBla9UqNbtPkMiwAAARM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Common web attack.
|
Hacking
SQL Injection
Web App Attack
|
|