๐ฎ๐ฉ
Incidents Response Neptus Team
2023-08-24 02:26:03
(3 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2023-08-16 04:32:32
(3 years ago)
Report Abuse IP
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Cynnexis Incident Response Team
2023-08-10 12:30:16
(3 years ago)
SQL Injection Attack triggered!
SQL Injection
๐ฎ๐ฉ
Burayot
2023-08-08 06:51:56
(3 years ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.104.81.11 (FR/France/vmi1314495.co ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.104.81.11 (FR/France/vmi1314495.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2023-08-06 17:07:44
(3 years ago)
[Mon Aug 07 00:07:42.679197 2023] [security2:error] [pid 30554:tid 139709019833920] [client 5.104.81 ...
show more
[Mon Aug 07 00:07:42.679197 2023] [security2:error] [pid 30554:tid 139709019833920] [client 5.104.81.11:49558] [client 5.104.81.11] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)<script[^>]*>[\\\\s\\\\S]*?" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "87"] [id "941110"] [msg "XSS Filter - Category 1: Script Tag Vector"] [data "Matched Data: <script> found within REQUEST_FILENAME: /does_not_exist\\x22\\x22><script>alert(document.domain)</script><img src=x request_line = GET /does_not_exist%22%22%3E%3Cscript%3Ealert%28document.domain%29%3C/script%3E%3Cimg%20src=x HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/does_not_exist\\"\\"><script>alert(document.domain)</script><img sr
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-08-06 16:20:32
(3 years ago)
[Sun Aug 06 23:20:30.599893 2023] [security2:error] [pid 20591:tid 140363725518400] [client 5.104.81 ...
show more
[Sun Aug 06 23:20:30.599893 2023] [security2:error] [pid 20591:tid 140363725518400] [client 5.104.81.11:54112] [client 5.104.81.11] ModSecurity: Access denied with code 403 (phase 2). Pattern match "." at ARGS_NAMES:redirect_to. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "501"] [id "921170"] [data "Matched Data: r found within ARGS_NAMES:redirect_to: redirect_to request_line = GET /demo/api/logout?redirect_to=/asdf%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/152/137/15/460"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/demo/api/logout"] [unique_id "ZM_ITry7mFuomNY_jU3KBwAAAG8"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[20704] [edYvgoOahPs] [ZM_ITry7mFuomNY_jU3KBwAAAG8] keep_alive=[0] [2023-08-06 23:20:30.599897] [R:ZM_ITry7mFuomNY_jU3
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-08-06 09:15:26
(3 years ago)
[Sun Aug 06 16:14:02.628144 2023] [security2:error] [pid 25664:tid 140514141660736] [client 5.104.81 ...
show more
[Sun Aug 06 16:14:02.628144 2023] [security2:error] [pid 25664:tid 140514141660736] [client 5.104.81.11:56678] [client 5.104.81.11] ModSecurity: Access denied with code 403 (phase 2). Found 1 byte(s) in REQUEST_URI outside range: 1-255. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "636"] [id "920270"] [msg "Invalid character in request (null character)"] [data "Matched Data: % found within REQUEST_URI: /index.php?option=com_userstatus&controller=../../../../../../../../../../etc/passwd\\x00 request_line = GET /index.php?option=com_userstatus&controller=../../../../../../../../../../etc/passwd%00 HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZM9kWkdP6TpM9mrl6zTp7QAAAIM"] [karangploso.jatim.bmk
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Jayalah Negeriku
2023-08-06 08:45:32
(3 years ago)
XSS
Hacking
SQL Injection
Web App Attack
๐ฎ๐ฉ
hermawan
2023-08-06 08:08:35
(3 years ago)
[Sun Aug 06 15:08:33.817541 2023] [security2:error] [pid 6942:tid 139674903352896] [client 5.104.81. ...
show more
[Sun Aug 06 15:08:33.817541 2023] [security2:error] [pid 6942:tid 139674903352896] [client 5.104.81.11:61516] [client 5.104.81.11] ModSecurity: Access denied with code 403 (phase 2). Pattern match "." at ARGS_NAMES:q. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "501"] [id "921170"] [data "Matched Data: q found within ARGS_NAMES:q: q request_line = POST /webadm/?q=moni_detail.do&action=gragh HTTP/1.1"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/152/137/15/460"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/webadm/"] [unique_id "ZM9VAf0ncvrLd4m0juyifAAAANQ"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[7063] [MXjZojzU1J0] [ZM9VAf0ncvrLd4m0juyifAAAANQ] keep_alive=[0] [2023-08-06 15:08:33.817548] [R:ZM9VAf0ncvrLd4m0juyifAAAANQ] UA:'Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36
...
show less
Hacking
Web App Attack
Anonymous
2023-08-06 05:58:52
(3 years ago)
XSS Attempt
Hacking
๐ฎ๐ฉ
penjaga BRIN
2023-08-06 04:03:09
(3 years ago)
XSS (Cross Site Scripting) attempt-112
Web App Attack
๐ฎ๐ฉ
hermawan
2023-08-05 17:29:00
(3 years ago)
[Sun Aug 06 00:28:58.838845 2023] [security2:error] [pid 25717:tid 140600275871296] [client 5.104.81 ...
show more
[Sun Aug 06 00:28:58.838845 2023] [security2:error] [pid 25717:tid 140600275871296] [client 5.104.81.11:57150] [client 5.104.81.11] ModSecurity: Access denied with code 403 (phase 2). Pattern match "." at ARGS_NAMES:action. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "501"] [id "921170"] [data "Matched Data: a found within ARGS_NAMES:action: action request_line = GET /wp-admin/admin-ajax.php?action=edd_download_search&s=1'+AND+(SELECT+1+FROM+(SELECT(SLEEP(6)))a)--+- HTTP/1.1"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/152/137/15/460"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZM6G2uGXS23n3ACmFQdgzQAAAIA"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[25847] [og43WTBLXVY] [ZM6G2uGXS23n3ACmFQdgzQAAAIA] keep_alive=[0] [2023-08-06 00:28:58.838848] [R:ZM6G2uGXS23n3ACmFQd
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2023-08-05 16:39:14
(3 years ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.104.81.11 (FR/France/vmi1314495.co ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.104.81.11 (FR/France/vmi1314495.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2023-08-05 02:43:17
(3 years ago)
LF_MODSEC: (mod_security) mod_security (id:960012) triggered by 5.104.81.11 (FR/France/vmi1314495.co ...
show more
LF_MODSEC: (mod_security) mod_security (id:960012) triggered by 5.104.81.11 (FR/France/vmi1314495.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2023-08-05 02:07:22
(3 years ago)
LF_MODSEC: (mod_security) mod_security (id:960024) triggered by 5.104.81.11 (JP/Japan/vmi1314495.con ...
show more
LF_MODSEC: (mod_security) mod_security (id:960024) triggered by 5.104.81.11 (JP/Japan/vmi1314495.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack