| IP | Hændelser |
|---|---|
198.51.100.20 | 6 |
198.51.100.11 | 6 |
198.51.100.33 | 6 |
198.51.100.24 | 6 |
198.51.100.17 | 5 |
198.51.100.29 | 5 |
198.51.100.14 | 4 |
198.51.100.34 | 4 |
198.51.100.35 | 4 |
198.51.100.28 | 4 |
| URI | Hændelser |
|---|---|
/?q=../../etc/passwd | 15 |
/api/v1/login | 15 |
/wp-login.php | 14 |
/xmlrpc.php | 13 |
/.env | 11 |
/index.php?id=1 | 9 |
/admin/ | 8 |
| Regel-ID | Udløsninger |
|---|---|
932100RCE — Unix commands |
21 |
913100Security scanner — User-Agent |
18 |
941100XSS via libinjection |
16 |
930100Path Traversal (/../) |
15 |
942100SQL Injection via libinjection |
15 |
| Tid | IP | URI | Type | Regel | Handling |
|---|---|---|---|---|---|
| 2026-10-12 00:40:27 | 198.51.100.14 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-12 00:34:30 | 198.51.100.31 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-12 00:26:29 | 198.51.100.20 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 23:10:54 | 198.51.100.11 |
/admin/ |
RCE | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 22:53:39 | 198.51.100.19 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 23:50:27 | 198.51.100.26 |
/wp-login.php |
XSS | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 22:53:39 | 198.51.100.11 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 21:04:58 | 198.51.100.34 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 20:58:51 | 198.51.100.34 |
/index.php?id=1 |
RCE | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 23:12:42 | 198.51.100.17 |
/.env |
RCE | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 23:42:07 | 198.51.100.13 |
/?q=../../etc/passwd |
Protocol Attack | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 20:05:05 | 198.51.100.15 |
/xmlrpc.php |
Scanner | 941100 XSS via libinjection |
Blokeret |
| 2026-10-11 21:30:15 | 198.51.100.25 |
/?q=../../etc/passwd |
XSS | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 22:17:01 | 198.51.100.35 |
/.env |
Scanner | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 22:10:11 | 198.51.100.11 |
/api/v1/login |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 16:50:27 | 198.51.100.20 |
/index.php?id=1 |
Protocol Attack | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 23:46:35 | 198.51.100.28 |
/wp-login.php |
XSS | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 18:52:48 | 198.51.100.22 |
/wp-login.php |
Scanner | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 20:57:51 | 198.51.100.32 |
/xmlrpc.php |
Scanner | 942100 SQL Injection via libinjection |
Blokeret |
| 2026-10-11 20:40:06 | 198.51.100.22 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 21:04:07 | 198.51.100.18 |
/xmlrpc.php |
RCE | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 14:16:24 | 198.51.100.12 |
/api/v1/login |
LFI/Path Traversal | 941100 XSS via libinjection |
Blokeret |
| 2026-10-11 20:28:33 | 198.51.100.16 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 21:31:05 | 198.51.100.33 |
/api/v1/login |
XSS | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 11:23:15 | 198.51.100.35 |
/.env |
RCE | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 21:48:22 | 198.51.100.12 |
/wp-login.php |
Protocol Attack | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 19:43:11 | 198.51.100.16 |
/admin/ |
SQL Injection | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 15:35:03 | 198.51.100.23 |
/wp-login.php |
XSS | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 15:39:35 | 198.51.100.24 |
/wp-login.php |
Scanner | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 11:37:27 | 198.51.100.30 |
/api/v1/login |
XSS | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 15:08:57 | 198.51.100.14 |
/index.php?id=1 |
LFI/Path Traversal | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 12:23:10 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 10:13:15 | 198.51.100.20 |
/.env |
SQL Injection | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 15:16:42 | 198.51.100.33 |
/.env |
Protocol Attack | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 13:46:31 | 198.51.100.17 |
/.env |
SQL Injection | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 06:30:12 | 198.51.100.25 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 15:05:03 | 198.51.100.12 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 16:49:56 | 198.51.100.21 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 17:03:49 | 198.51.100.28 |
/admin/ |
SQL Injection | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 13:21:12 | 198.51.100.20 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 17:19:47 | 198.51.100.34 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Blokeret |
| 2026-10-11 15:09:11 | 198.51.100.24 |
/admin/ |
RCE | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 15:51:15 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 20:23:53 | 198.51.100.13 |
/?q=../../etc/passwd |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 19:28:03 | 198.51.100.17 |
/index.php?id=1 |
XSS | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 20:57:42 | 198.51.100.35 |
/.env |
Scanner | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 17:01:59 | 198.51.100.14 |
/xmlrpc.php |
XSS | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 13:00:09 | 198.51.100.11 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 08:33:15 | 198.51.100.33 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 20:39:32 | 198.51.100.17 |
/wp-login.php |
XSS | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 17:39:37 | 198.51.100.33 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 10:32:09 | 198.51.100.26 |
/api/v1/login |
Scanner | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-11 15:59:35 | 198.51.100.28 |
/.env |
LFI/Path Traversal | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 13:53:51 | 198.51.100.32 |
/api/v1/login |
Protocol Attack | 930100 Path Traversal (/../) |
Blokeret |
| 2026-10-11 07:38:57 | 198.51.100.23 |
/index.php?id=1 |
Protocol Attack | 942100 SQL Injection via libinjection |
Blokeret |
| 2026-10-11 14:31:47 | 198.51.100.24 |
/admin/ |
RCE | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 11:37:23 | 198.51.100.35 |
/?q=../../etc/passwd |
SQL Injection | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-11 13:41:09 | 198.51.100.20 |
/?q=../../etc/passwd |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-10 19:31:45 | 198.51.100.21 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 13:57:21 | 198.51.100.11 |
/?q=../../etc/passwd |
Scanner | 913100 Security scanner — User-Agent |
Blokeret |
| 2026-10-11 05:44:27 | 198.51.100.19 |
/?q=../../etc/passwd |
XSS | 930100 Path Traversal (/../) |
Blokeret |
| 2026-10-11 13:34:32 | 198.51.100.21 |
/?q=../../etc/passwd |
XSS | 941100 XSS via libinjection |
Blokeret |
| 2026-10-10 18:40:23 | 198.51.100.24 |
/index.php?id=1 |
LFI/Path Traversal | 941100 XSS via libinjection |
Registreret |
| 2026-10-10 15:02:21 | 198.51.100.29 |
/index.php?id=1 |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Blokeret |
| 2026-10-10 14:05:47 | 198.51.100.15 |
/admin/ |
RCE | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 19:38:12 | 198.51.100.29 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 20:02:09 | 198.51.100.17 |
/xmlrpc.php |
RCE | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 17:49:31 | 198.51.100.20 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Registreret |
| 2026-10-10 16:20:11 | 198.51.100.24 |
/api/v1/login |
Scanner | 941100 XSS via libinjection |
Blokeret |
| 2026-10-11 10:20:15 | 198.51.100.19 |
/.env |
Scanner | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 18:37:37 | 198.51.100.29 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Blokeret |
| 2026-10-10 13:22:17 | 198.51.100.12 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 16:10:27 | 198.51.100.28 |
/wp-login.php |
XSS | 942100 SQL Injection via libinjection |
Registreret |
| 2026-10-10 11:37:36 | 198.51.100.33 |
/.env |
RCE | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 04:12:03 | 198.51.100.18 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 15:42:57 | 198.51.100.26 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Blokeret |
| 2026-10-11 09:13:15 | 198.51.100.14 |
/admin/ |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-10 10:43:49 | 198.51.100.33 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Registreret |
| 2026-10-11 03:29:03 | 198.51.100.27 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Registreret |
| 2026-10-11 07:09:45 | 198.51.100.11 |
/.env |
SQL Injection | 941100 XSS via libinjection |
Blokeret |
| 2026-10-11 12:32:27 | 198.51.100.34 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Blokeret |
| 2026-10-11 19:31:18 | 198.51.100.24 |
/api/v1/login |
Protocol Attack | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 11:20:57 | 198.51.100.32 |
/xmlrpc.php |
Scanner | 942100 SQL Injection via libinjection |
Blokeret |
| 2026-10-11 03:02:53 | 198.51.100.32 |
/admin/ |
Protocol Attack | 932100 RCE — Unix commands |
Registreret |
| 2026-10-11 05:29:39 | 198.51.100.27 |
/wp-login.php |
Scanner | 913100 Security scanner — User-Agent |
Registreret |
ModSecurity med OWASP Core Rule Set blokerer overordentlig meget og skriver om næsten alt af det til en revisionslog, hvis format er lavet til maskiner. Denne side gør det til noget læsbart: hvilke forespørgsler der blev blokeret, hvilken regel der udløstes, hvad anomali-scoren var, og hvor forespørgslen kom fra.
Grunden til at kigge her jævnligt er falske positiver. Core Rule Set er bevidst strengt og blokerer på standardniveauet legitim trafik i de fleste virkelige applikationer: filoverførsler, redaktører med formateret tekst og alt, der sender markup eller SQL-lignende strenge, er de sædvanlige ofre. Mønsteret at genkende er det samme regel-ID, der udløses gang på gang mod det samme endepunkt fra mange forskellige adresser. Det er ikke et angreb, det er din egen applikation, der bliver taget.
Hold undtagelsen snæver, når du finder en: udelad netop den regel for netop den parameter på netop den sti, aldrig hele reglen og endnu mindre hele kategorien. Siden viser også det aktive regelsæt, så du efter en ændring kan bekræfte, hvad der faktisk er indlæst.