๐จ๐ฆ
JuicyJ
2025-01-07 08:58:13
(1 year ago)
Excessive crawling/scraping
Web App Attack
๐ฟ๐ฆ
maximonline.co.za
2025-01-04 23:17:02
(1 year ago)
Attempts at SQL injection.
SQL Injection
Web App Attack
๐ฉ๐ช
conseilgouz
2025-01-04 19:38:52
(1 year ago)
vee-12 : Block return, carriage return, ... characters=>/component/weblinks/weblink/53-motorlegend?I ...
show more
vee-12 : Block return, carriage return, ... characters=>/component/weblinks/weblink/53-motorlegend?Itemid=1029&Itemid=%27&catid=15&task=weblink....(')
show less
Hacking
๐ซ๐ท
COMAITE
2025-01-04 18:48:16
(1 year ago)
SQL injection attempt from 51.81.173.237.
Web App Attack
๐ฐ๐ท
han
2025-01-03 00:18:00
(1 year ago)
SQL Injection
SQL Injection
๐ง๐ช
taivas.nl
2025-01-03 00:02:16
(1 year ago)
Bad_requests
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2025-01-02 23:27:49
(1 year ago)
valueaddedpromotions.com.au:443 51.81.173.237 - - [03/Jan/2025:10:27:31 +1100] "GET /promo/www/produ ...
show more
valueaddedpromotions.com.au:443 51.81.173.237 - - [03/Jan/2025:10:27:31 +1100] "GET /promo/www/product/productlist.php?category=01675&main-category=headwear&name=beanies&page=12 HTTP/1.1" 404 146197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
valueaddedpromotions.com.au:443 51.81.173.237 - - [03/Jan/2025:10:27:33 +1100] "GET /promo/www/product/productlist.php?category=01675&category=%27&main-category=headwear&name=beanies&page=12 HTTP/1.1" 404 146212 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
valueaddedpromotions.com.au:443 51.81.173.237 - - [03/Jan/2025:10:27:35 +1100] "GET /promo/www/product/productlist.php?category=01675&main-category=headwear&main-category=%27&name=beanies&page=12 HTTP/1.1" 404 146215 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
valueaddedpromotio
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 23:24:39
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 18:24:33.418062 2025] [security2:error] [pid 16506:tid 16506] [client 51.81.173.237:59851] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mooseled.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mooseled.com"] [uri "/index.php"] [unique_id "Z3cgMQXgDf_kSm0s7oeHpwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 23:00:09
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 18:00:04.116865 2025] [security2:error] [pid 20229:tid 20229] [client 51.81.173.237:62296] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mail.panmaneecnc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mail.panmaneecnc.com"] [uri "/index.php"] [unique_id "Z3cadNgNUfIaKqks0Hg4ZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 22:37:27
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 17:37:20.759576 2025] [security2:error] [pid 2879:tid 2879] [client 51.81.173.237:56437] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.southtncardio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.southtncardio.com"] [uri "/index.php"] [unique_id "Z3cVIFYZEg1xImHR0iPF6AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-01-02 22:29:13
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 21:42:54
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 16:42:47.351212 2025] [security2:error] [pid 18103:tid 18103] [client 51.81.173.237:58927] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.laboquimia.es|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.laboquimia.es"] [uri "/catalogo/producto.php"] [unique_id "Z3cIVxZ0hhmYZeAdRl0gigAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-01-02 21:01:28
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-01-02 20:54:49
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 15:54:44.749341 2025] [security2:error] [pid 1423933:tid 1423958] [client 51.81.173.237:58198] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.volcano-sa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.volcano-sa.com"] [uri "/products.php"] [unique_id "Z3b9FMlpPXBaPYXk_oTpuQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-02 20:34:00
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the ...
show more
(mod_security) mod_security (id:210350) triggered by 51.81.173.237 (ip237.ip-51-81-173.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 02 15:33:55.562758 2025] [security2:error] [pid 762745:tid 762745] [client 51.81.173.237:55017] [client 51.81.173.237] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.jwwsb.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.jwwsb.org"] [uri "/index.php"] [unique_id "Z3b4MzIx0JFgMfesFAOQ-AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack