๐ช๐ธ
el-brujo
2025-10-30 14:41:49
(10 months ago)
Cloudflare WAF: Request Path: /hacking/bypass-php-credenciales-harcodeadas/%27%29%2F%2A%2A%2FORDER%2 ...
show more
Cloudflare WAF: Request Path: /hacking/bypass-php-credenciales-harcodeadas/%27%29%2F%2A%2A%2FORDER%2F%2A%2A%2FBY%2F%2A%2A%2F9893--%2F%2A%2A%2FyKyM Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.0 Unique/97.7.7239.70 Action: block Source: firewallManaged ASN Description: PINATON-AS Country: RU Method: GET Timestamp: 2025-10-30T14:41:49Z ruleId: 3ef34ac2e1df4ed9900c9966128f1556. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2025-10-30 05:47:50
(10 months ago)
5.183.129.58 - - [30/Oct/2025:05:47:49 +0000] "GET /bothole/stinkwell.php?t=35443&cthq=2306%20AND%20 ...
show more
5.183.129.58 - - [30/Oct/2025:05:47:49 +0000] "GET /bothole/stinkwell.php?t=35443&cthq=2306%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 307 6447 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
SQL Injection
๐ช๐ธ
el-brujo
2025-10-30 03:54:40
(10 months ago)
Cloudflare WAF: Request Path: /php/html_y_php-t439747.0.html Request Query: ?yQEM=1486%20AND%201%3D1 ...
show more
Cloudflare WAF: Request Path: /php/html_y_php-t439747.0.html Request Query: ?yQEM=1486%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8.1 Safari/605.1.15 Action: block Source: firewallManaged ASN Description: PINATON-AS Country: RU Method: GET Timestamp: 2025-10-30T03:54:40Z ruleId: 4c580ea1b5174183b7f5e940b3de2e0a. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2025-10-30 02:17:16
(10 months ago)
GET /how-to-book.php/ HTTP/1.1
Web App Attack
๐ซ๐ท
LRob
2025-10-30 02:15:03
(10 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฆ๐บ
afleventoffice.com.au
2025-10-29 22:39:39
(10 months ago)
GET /premium/how-to-book.php/ HTTP/1.1
Web App Attack
Anonymous
2025-10-28 09:47:41
(10 months ago)
5.183.129.58 - - [28/Oct/2025:09:47:41 +0000] "GET /bothole/stinkwell.php?p=467263&njrP=4538%20AND%2 ...
show more
5.183.129.58 - - [28/Oct/2025:09:47:41 +0000] "GET /bothole/stinkwell.php?p=467263&njrP=4538%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 307 6449 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.0"
...
show less
SQL Injection
๐ฉ๐ช
london2038.com
2025-10-27 23:09:54
(10 months ago)
Probing for exploits
5.183.129.58 - - [28/Oct/2025:00:09:13 +0100] "GET /forum/hellgate-london-modif ...
show more
Probing for exploits
5.183.129.58 - - [28/Oct/2025:00:09:13 +0100] "GET /forum/hellgate-london-modification-discussion/ce-hex-editing-help-needed/?xuHS=3081%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 422 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:141.0) Gecko/20100101 Firefox/141.0"
5.183.129.58 - - [28/Oct/2025:00:09:50 +0100] "GET /forum/hellgate-london-modification-guides/tutorial-on-'hexing'-your-character/?RkSs=5463%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
exxos
2025-10-27 16:03:01
(10 months ago)
Attacks with Bad user agents
Hacking
๐ช๐ธ
el-brujo
2025-10-25 11:30:26
(11 months ago)
Cloudflare WAF: Request Path: /nivel_web/google_dork_para_inyecciones_sql-t305374.0.html Request Que ...
show more
Cloudflare WAF: Request Path: /nivel_web/google_dork_para_inyecciones_sql-t305374.0.html Request Query: ?xtJV=1326%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: PINATON-AS Country: RU Method: GET Timestamp: 2025-10-25T11:30:26Z ruleId: 4c580ea1b5174183b7f5e940b3de2e0a. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฑ๐ป
garmtech.com
2025-10-19 20:45:47
(11 months ago)
IM360 WAF: SQL Injection Attack: Common DB Names Detected
SQL Injection
๐บ๐ธ
SaratogaWX
2025-10-18 14:54:00
(11 months ago)
Various URLencoded SQL injection attempts on GET mode URL arguments (all unsuccessful)
Hacking
SQL Injection
Anonymous
2025-10-17 22:31:47
(11 months ago)
5.183.129.58 - - [17/Oct/2025:22:31:46 +0000] "GET /bothole/stinkwell.php?t=24400&AUxv=9897%20AND%20 ...
show more
5.183.129.58 - - [17/Oct/2025:22:31:46 +0000] "GET /bothole/stinkwell.php?t=24400&AUxv=9897%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23 HTTP/1.1" 307 6447 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
...
show less
SQL Injection
๐ซ๐ท
dynamix
2025-10-17 22:00:45
(11 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-08 14:58:48
(11 months ago)
(mod_security) mod_security (id:211190) triggered by 5.183.129.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 5.183.129.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 10:58:41.989488 2025] [security2:error] [pid 15050:tid 15058] [client 5.183.129.58:55202] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||seips.org|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /test.php?ixGy=5365%20AND%201%3D1%20UNION%20ALL%20SELECT%201%2CNULL%2C%27%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E%27%2Ctable_name%20FROM%20information_schema.tables%20WHERE%202%3E1--%2F%2A%2A%2F%3B%20EXEC%20xp_cmdshell%28%27cat%20..%2F..%2F..%2Fetc%2Fpasswd%27%29%23"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seips.org"] [uri "/test.php"] [unique_id "aOZ8IUfqNjjrdKf4fWEA0AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack