hermawan
12 Nov 2022
[Sat Nov 12 15:40:09.772707 2022] [-:error] [pid 56377:tid 139933798753856] [client 95.108.213.55:44 ... show more [Sat Nov 12 15:40:09.772707 2022] [-:error] [pid 56377:tid 139933798753856] [client 95.108.213.55:44544] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/informasi-angin-pelayaran-wilayah-jawa-timur/1797-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-kediri/kalender-tanam-katam-terpadu-kecamatan-wates-kabupaten-kediri/kalender-tanam-katam-terpadu-kecamatan-wates-kabupaten-kediri-tahun-2016-2017/2124-kalender..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/informasi-a
... show less
Hacking
Web App Attack
hermawan
11 Nov 2022
[Sat Nov 12 02:35:41.414148 2022] [-:error] [pid 42794:tid 139869061756480] [client 95.108.213.55:59 ... show more [Sat Nov 12 02:35:41.414148 2022] [-:error] [pid 42794:tid 139869061756480] [client 95.108.213.55:59174] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/animasi-prakiraan-cuaca-indonesia/1891-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-banyuwangi/kalender-tanam-katam-terpadu-kecamatan-glagah-kabupaten-banyuwangi/kalender-tanam-katam-terpadu-kecamatan-glagah-kabupaten-banyuwangi-tahun-2016-2017/2183-kalen..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/animasi-pra
... show less
Hacking
Web App Attack
hermawan
11 Nov 2022
[Fri Nov 11 23:39:40.037795 2022] [-:error] [pid 128255:tid 140256370140736] [client 95.108.213.55:3 ... show more [Fri Nov 11 23:39:40.037795 2022] [-:error] [pid 128255:tid 140256370140736] [client 95.108.213.55:39752] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-musim/272-prakiraan-musim-kemarau/prakiraan-sifat-hujan-musim-kemarau HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-musim/272-prakiraan-musim-kemarau/prakiraan-sifat-hujan-musim-kemarau"] [unique_id "Y256zKVK9D99V-WL3Z02mwAAABk"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[128277] [WTU1iUS9iis] [Y256zKVK9D99V-WL3Z02mwAAABk] keep_alive=[0] [2022-11-11 23:39:40.0
... show less
Hacking
Web App Attack
hermawan
10 Nov 2022
[Fri Nov 11 10:22:44.452422 2022] [-:error] [pid 171351:tid 139674253624896] [client 95.108.213.55:6 ... show more [Fri Nov 11 10:22:44.452422 2022] [-:error] [pid 171351:tid 139674253624896] [client 95.108.213.55:64332] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555559558-prakiraan-bulanan-curah-hujan-bulan-september-tahun-2022-update-dari-analisis-bulan-juni-tahun-2022-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555559558-prakiraan-bulanan-curah-hujan-bulan-september-tahun-2022-update-dari-analisis-bulan-juni-
... show less
Hacking
Web App Attack
hermawan
10 Nov 2022
[Fri Nov 11 03:10:29.666533 2022] [-:error] [pid 41660:tid 139674406217280] [client 95.108.213.55:45 ... show more [Fri Nov 11 03:10:29.666533 2022] [-:error] [pid 41660:tid 139674406217280] [client 95.108.213.55:45682] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/pengaduan/1341-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-malang/kalender-tanam-katam-terpadu-kecamatan-tirto-yudo-kabupaten-malang/kalender-tanam-katam-terpadu-kecamatan-tirto-yudo-kabupaten-malang-tahun-2016-2017 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/pengaduan/1341-klimatologi/agroklimatologi/k
... show less
Hacking
Web App Attack
hermawan
10 Nov 2022
[Thu Nov 10 23:47:49.257452 2022] [-:error] [pid 175623:tid 140282834048576] [client 95.108.213.55:5 ... show more [Thu Nov 10 23:47:49.257452 2022] [-:error] [pid 175623:tid 140282834048576] [client 95.108.213.55:51302] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/3871-klimatologi/555557762-refleksi-kejadian-bencana-terkait-cuaca-iklim-dan-gempa-bumi-yang-signifikan-pada-tahun-2019-serta-apa-yang-mungkin-terjadi-outlook-pada-tahun-2020 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/3871-klimatologi/555557762-refleksi-kejadian-bencana-terkait-cuaca-iklim-dan-gempa-bumi-yang-signifikan-pad
... show less
Hacking
Web App Attack
hermawan
10 Nov 2022
[Thu Nov 10 13:52:57.170969 2022] [-:error] [pid 49609:tid 139928992097856] [client 95.108.213.55:43 ... show more [Thu Nov 10 13:52:57.170969 2022] [-:error] [pid 49609:tid 139928992097856] [client 95.108.213.55:43468] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555558816-infografis-bulanan-prakiraan-hujan-bulan-juli-agustus-september-tahun-2021-update-dari-analisis-bulan-mei-2021-di-provinsi-jawa-timur-2 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555558816-infografis-bulanan-prakiraan-hujan-bulan-juli-a
... show less
Hacking
Web App Attack
rh24
09 Nov 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Russia/95-108-213-55.spider.yandex.com) show less
Bad Web Bot
hermawan
08 Nov 2022
[Wed Nov 09 11:51:00.436561 2022] [-:error] [pid 26296:tid 139747563292224] [client 95.108.213.55:33 ... show more [Wed Nov 09 11:51:00.436561 2022] [-:error] [pid 26296:tid 139747563292224] [client 95.108.213.55:33502] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-iklim/analisis-musim/perbandingan-awal-musim-hujan-dengan-normalnya HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-musim/perbandingan-awal-musim-hujan-dengan-normalnya"] [unique_id "Y2sxtMVD7eeL_DTE7Tz3BAAAALU"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[26324] [AXgoZ/JlDdU] [Y2sxtMVD7eeL_DTE7Tz3BAAAALU] keep_alive=[0] [2022-11-09 11:51:00.436565] [
... show less
Hacking
Web App Attack
hermawan
08 Nov 2022
[Tue Nov 08 12:42:36.122489 2022] [-:error] [pid 39182:tid 140173146707520] [client 95.108.213.55:43 ... show more [Tue Nov 08 12:42:36.122489 2022] [-:error] [pid 39182:tid 140173146707520] [client 95.108.213.55:43714] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexMetrika/2.0; +http://yandex.com/bots yabs01) request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/"] [unique_id "Y2nsTBwRXwkp5kSZk9yVxQAAAA0"] [staklim-malang.info] [staklim-malang.info] top=[39217] [/4XcAV/wQdE] [Y2nsTBwRXwkp5kSZk9yVxQAAAA0] keep_alive=[0] [2022-11-08 12:42:36.122493] [R:Y2nsTBwRXwkp5kSZk9yVxQAAAA0] UA:'Mozilla/5.0 (compatible; YandexMetrika/2.0; +http://yandex.com/bots yabs01)' Host:'staklim-malang.info' ACCEPT:'*/*' Accept-Encoding:'gzip,deflate
... show less
Hacking
Web App Attack
hermawan
07 Nov 2022
[Tue Nov 08 02:12:57.638918 2022] [-:error] [pid 44257:tid 139629153908288] [client 95.108.213.55:49 ... show more [Tue Nov 08 02:12:57.638918 2022] [-:error] [pid 44257:tid 139629153908288] [client 95.108.213.55:49810] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/monitoring-hari-tanpa-hujan-berturut-turut/3950-monitoring-hari-tanpa-hujan-berturut-turut-propinsi-jawa-timur/monitoring-hari-tanpa-hujan-berturut-turut-dasarian-provinsi-jawa-timur/monitoring-hari-tanpa-hujan-berturut-turut-dasarian-provinsi-jawa-timur-tahun-2019/494-monitoring-hari-tanpa-hujan-berturut-turut-update-20-maret-2019-di-provinsi-jawa-timu..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/monitoring-
... show less
Hacking
Web App Attack
hermawan
06 Nov 2022
[Mon Nov 07 11:17:28.105974 2022] [-:error] [pid 34901:tid 140090063828544] [client 95.108.213.55:43 ... show more [Mon Nov 07 11:17:28.105974 2022] [-:error] [pid 34901:tid 140090063828544] [client 95.108.213.55:43576] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/2015-04-16-10-15-17/1047-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-pacitan/kalender-tanam-katam-terpadu-kecamatan-tulakan-kabupaten-pacitan HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/2015-04-16-10-15-17/1047-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provins
... show less
Hacking
Web App Attack
hermawan
05 Nov 2022
[Sat Nov 05 11:58:18.363848 2022] [-:error] [pid 20623:tid 139697187628608] [client 95.108.213.55:45 ... show more [Sat Nov 05 11:58:18.363848 2022] [-:error] [pid 20623:tid 139697187628608] [client 95.108.213.55:45122] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-of-all-tags/3378 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/3378"] [unique_id "Y2Xtape0vCNVZUSgUJIpagAAADI"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[20645] [RbfhCcLMxhU] [Y2Xtape0vCNVZUSgUJIpagAAADI] keep_alive=[0] [2022-11-05 11:58:18.363851] [R:Y2Xtape0vCNVZUSgUJIpagAAADI] UA:'Mozilla/5.0 (compatible; YandexBot/3.
... show less
Hacking
Web App Attack
hermawan
04 Nov 2022
[Sat Nov 05 00:06:05.934378 2022] [-:error] [pid 44312:tid 140104379020864] [client 95.108.213.55:48 ... show more [Sat Nov 05 00:06:05.934378 2022] [-:error] [pid 44312:tid 140104379020864] [client 95.108.213.55:48084] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman/555558684-prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-jawa-timur-untuk-bulan-mei-tahun-2021-update-dari-analisis-bulan-maret-2021 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman/555558684-prakiraan-bulanan-tingkat-
... show less
Hacking
Web App Attack
hermawan
04 Nov 2022
[Fri Nov 04 16:19:10.331604 2022] [-:error] [pid 55606:tid 140678923167296] [client 95.108.213.55:37 ... show more [Fri Nov 04 16:19:10.331604 2022] [-:error] [pid 55606:tid 140678923167296] [client 95.108.213.55:37428] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Y2TZDturvSP6A7cRilKgPgAAAJ4"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[55636] [PewCkdE7JpQ] [Y2TZDturvSP6A7cRilKgPgAAAJ4] keep_alive=[0] [2022-11-04 16:19:10.331607] [R:Y2TZDturvSP6A7cRilKgPgAAAJ4] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack