๐ฎ๐ฉ
hermawan
2022-03-02 15:26:34
(4 years ago)
[Thu Mar 03 03:26:32.350400 2022] [:error] [pid 146054:tid 140731851208448] [client 54.70.162.253:48 ...
show more
[Thu Mar 03 03:26:32.350400 2022] [:error] [pid 146054:tid 140731851208448] [client 54.70.162.253:48862] [client 54.70.162.253] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-3.3.2/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "127"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "staklim-malang.info"] [uri "/.env"] [unique_id "Yh_S-MS5MYNHb5lj_nvg7QAAAM4"]
...
show less
Hacking
Web App Attack
๐ฒ๐พ
syokadmin
2022-03-02 14:19:16
(4 years ago)
(PERMBLOCK) 54.70.162.253 (US/United States/ec2-54-70-162-253.us-west-2.compute.amazonaws.com) has h ...
show more
(PERMBLOCK) 54.70.162.253 (US/United States/ec2-54-70-162-253.us-west-2.compute.amazonaws.com) has had more than 2 temp blocks in the last 86400 secs
show less
Brute-Force
๐ฒ๐พ
syokadmin
2022-03-02 12:18:54
(4 years ago)
(mod_security) mod_security (id:210492) triggered by 54.70.162.253 (US/United States/ec2-54-70-162-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.70.162.253 (US/United States/ec2-54-70-162-253.us-west-2.compute.amazonaws.com): 1 in the last 3600 secs
show less
Brute-Force
๐ธ๐ฎ
MateHekur
2022-02-28 16:40:42
(4 years ago)
2022-02-28 22:40:40 -- 54.70.162.253 GET /.env
Web App Attack
๐ฌ๐ง
Shadymint
2022-02-28 05:21:04
(4 years ago)
url probing from IP marked as abusive
Web App Attack
๐ฌ๐ง
headwall
2022-02-28 00:32:32
(4 years ago)
Probe for WordPress internals file .env by client 54.70.162.253 on local port 443
Web App Attack
๐ฉ๐ช
Raist
2022-02-27 23:16:55
(4 years ago)
Auto reported : Massive generation of 404/403
Web App Attack
Anonymous
2022-02-27 22:15:01
(4 years ago)
Configuration snooping (/.env):
54.70.162.253 - - [28/Feb/2022:03:01:49 +0000] "GET /.env HTTP/1.1" ...
show more
Configuration snooping (/.env):
54.70.162.253 - - [28/Feb/2022:03:01:49 +0000] "GET /.env HTTP/1.1" 404 241 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
๐ฉ๐ช
jasperedv.de
2022-02-27 21:20:50
(4 years ago)
Apache Login - Brutforcing
Brute-Force
Web App Attack
๐ฉ๐ช
Avocuard
2022-02-27 19:57:41
(4 years ago)
Attempt to access .env | Ignores robots.txt | User agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKi ...
show more
Attempt to access .env | Ignores robots.txt | User agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Bad Web Bot
๐ฑ๐บ
conseilgouz
2022-02-27 19:53:25
(4 years ago)
ale-17 : Block hidden directories=>/.env(/)
Hacking
Anonymous
2022-02-27 19:52:42
(4 years ago)
54.70.162.253 - - [28/Feb/2022:01:52:41 +0100] "GET /.env HTTP/1.1" 403 6948 "-" "Mozilla/5.0 (X11; ...
show more
54.70.162.253 - - [28/Feb/2022:01:52:41 +0100] "GET /.env HTTP/1.1" 403 6948 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" ...
show less
Web App Attack
Anonymous
2022-02-27 19:45:43
(4 years ago)
Configuration snooping (/.env):
54.70.162.253 - - [28/Feb/2022:00:45:43 +0000] "GET /.env HTTP/1.1" ...
show more
Configuration snooping (/.env):
54.70.162.253 - - [28/Feb/2022:00:45:43 +0000] "GET /.env HTTP/1.1" 200 234 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
๐ฉ๐ช
alps.one
2022-02-27 14:50:13
(4 years ago)
(mod_security) mod_security (id:949110) triggered by 54.70.162.253 (US/United States/ec2-54-70-162-2 ...
show more
(mod_security) mod_security (id:949110) triggered by 54.70.162.253 (US/United States/ec2-54-70-162-253.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
ut-addicted.com
2022-02-27 14:15:03
(4 years ago)
\[Sun Feb 27 20:15:02.078779 2022\] \[:error\] \[pid 16292:tid 139915341829888\] \[client 54.70.162. ...
show more
\[Sun Feb 27 20:15:02.078779 2022\] \[:error\] \[pid 16292:tid 139915341829888\] \[client 54.70.162.253:59862\] \[client 54.70.162.253\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "crx.it"\] \[uri "/.env"\] \[unique_id "YhvNtj38og9xG@loe8xqBwAAAMc"\]
show less
Brute-Force
Web App Attack