AbuseIPDB » 66.45.249.125
66.45.249.125 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 0%: ?
| ISP |
Interserver, Inc
|
| Usage Type |
Data Center/Web Hosting/Transit
|
| ASN |
AS19318
|
| Hostname(s) |
vps3228901.trouble-free.net
|
| Domain Name |
interserver.net
|
| Country |
๐บ๐ธ
United States of America
|
| City |
New York City, New York
|
IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
IP Abuse Reports for 66.45.249.125:
This IP address has been reported a total of
9
times from
8 distinct
sources.
66.45.249.125 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
| Reporter |
IoA Timestamp (UTC)
|
Comment |
Categories |
|
|
๐บ๐ธ
TheMadBeaker
|
|
Fail2Ban Ban Triggered
HTTP SQL Injection Attempt
|
Hacking
SQL Injection
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Tue Dec 12 23:54:05.371520 2023] [security2:error] [pid 234346:tid 140487029679680] [client 66.45.2 ...
show more
[Tue Dec 12 23:54:05.371520 2023] [security2:error] [pid 234346:tid 140487029679680] [client 66.45.249.125:65337] [client 66.45.249.125] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:^\\\\s*[\\"'`;]+|[\\"'`]+\\\\s*$)" at ARGS:option. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1021"] [id "942111"] [msg "SQL Injection Attack: Common Injection Testing Detected"] [data "Matched Data: ' found within ARGS:option: com_tags' request_line = GET /index.php?option=com_tags%27&view=tag&id=376-ombrometer HTTP/1.1"] [severity "WARNING"] [ver "OWASP_CRS/4.0.0-rc2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ZXiQInaSMwYIb2ij-mfkMAAAAOc"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[234464] [26pQ5ZJjgy0] [
...
show less
|
Hacking
Web App Attack
|
|
|
๐ซ๐ท
conseilgouz
|
|
sae-12 : Block return, carriage return, ... characters=>/index.php?option=com_content%27&view=ar ...
show more
sae-12 : Block return, carriage return, ... characters=>/index.php?option=com_content%27&view=article&id=71&Itemid=435(')
show less
|
Hacking
|
|
|
๐ต๐ฑ
mkrufczyk
|
|
SQL injection attempt
|
Bad Web Bot
Web App Attack
|
|
|
๐ฆ๐บ
ozisp.com.au
|
|
US_Interserver,_<33>1700092959 [1:19439:10] SQL 1 = 1 - possible sql injection attempt [Classificati ...
show more
US_Interserver,_<33>1700092959 [1:19439:10] SQL 1 = 1 - possible sql injection attempt [Classification: Web Application Attack] [Priority: 1] {TCP} 66.45.249.125:54117
show less
|
Hacking
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Thu Nov 16 04:30:54.233320 2023] [security2:error] [pid 94246:tid 140358843356736] [client 66.45.24 ...
show more
[Thu Nov 16 04:30:54.233320 2023] [security2:error] [pid 94246:tid 140358843356736] [client 66.45.249.125:52677] [client 66.45.249.125] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?i)(?:(?:^|=)[\\\\s\\\\v]*(?:t[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?-@_a-\\\\{]*)?\\\\x5c?i[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?-@_a-\\\\{]*)?\\\\x5c?m[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\ ..." at REQUEST_HEADERS:referer. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "2004"] [id "932239"] [msg "Remote Command Execution: Unix Command Injection found in user-agent or referer header"] [data "Matched Data: &id found within REQUEST_HEADERS:referer: https://karangploso.jatim.bmkg.go.id/administrator/index.php?option=com_tags&task=tag.edit&id=2507"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc2"] [tag "
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฟ๐ฆ
vuurklip
|
|
Attempted SQL injection
|
SQL Injection
|
|
|
๐ฎ๐ฉ
penjaga BRIN
|
|
SQL injection attempt.-111
|
Brute-Force
|
|
|
Anonymous
|
|
| Multiple SQL injection attempts from same source ip.
|
Hacking
SQL Injection
Web App Attack
|
|
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: