๐บ๐ธ
masterguru
2025-05-18 10:53:21
(1 year ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-124)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-18 09:55:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 05:55:33.653799 2025] [security2:error] [pid 1115917:tid 1115917] [client 59.8.29.83:54342] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||csme-eprr.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "csme-eprr.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "aCmulX6mAnoirwcymH9_zQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-18 09:17:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 05:17:42.893363 2025] [security2:error] [pid 4022159:tid 4022159] [client 59.8.29.83:45012] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dietzengineers.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dietzengineers.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "aCmltn-uCkWJRuOCoEmP7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2025-05-18 09:07:07
(1 year ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-05-18 08:02:07
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2025-05-18 07:08:04
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-18 06:50:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 02:50:01.501727 2025] [security2:error] [pid 2590572:tid 2590572] [client 59.8.29.83:43462] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aguasolar.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aguasolar.com"] [uri "/tienda/ALFA_DATA/.vscode/Telerik.Web.UI.WebResource.axd"] [unique_id "aCmDGZvbabNtFEXInPe67wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2025-05-18 06:16:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 59.8.29.83 (KR/South Korea/-): N in the last X ...
show more
(mod_security) mod_security (id:210492) triggered by 59.8.29.83 (KR/South Korea/-): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-18 06:05:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 02:05:43.327354 2025] [security2:error] [pid 2754637:tid 2754637] [client 59.8.29.83:34610] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tallahasseepartybuses.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tallahasseepartybuses.com"] [uri "/ALFA_DATA/.vscode/Telerik.Web.UI.WebResource.axd"] [unique_id "aCl4t9qJYKbgXqiEUsz3jAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2025-05-18 06:04:30
(1 year ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2025-05-18 05:12:44
(1 year ago)
2 attacks on password grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-17 21:08:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 17 17:08:49.074042 2025] [security2:error] [pid 3939020:tid 3939020] [client 59.8.29.83:35176] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||4940brooklinedr.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4940brooklinedr.com"] [uri "/ALFA_DATA/.vscode/Telerik.Web.UI.WebResource.axd"] [unique_id "aCj64cOSwxAYOCoHm7B1cwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-17 20:08:07
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 17 16:07:59.784103 2025] [security2:error] [pid 1746710:tid 1746710] [client 59.8.29.83:49858] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sammour.com|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sammour.com"] [uri "/ALFA_DATA/.vscode/Telerik.Web.UI.WebResource.axd"] [unique_id "aCjsn5eVtl-wzCJBeaHwqwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-17 17:02:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 59.8.29.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 17 13:02:04.584086 2025] [security2:error] [pid 3980032:tid 3980032] [client 59.8.29.83:37060] [client 59.8.29.83] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bwill.dev|F|2"] [data ".web.ui.webresource.axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bwill.dev"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "aCjBDDHXx6jRG67GyZjr7QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2025-05-17 16:59:01
(1 year ago)
Web App Attack
Web App Attack