ModSecurity

ModSecurity WAF
Caché: 23:54:38 Actualizar
ModSecurity Activo
Hoy
2788
Bloqueado
160
Total en la muestra
2788
IP únicas
10
Lista de reglas no disponible: actualice el wrapper monitor-modsec añadiendo la sección ---RULES--- (consulte la FAQ).
Tipos de ataques
RCE
19
Protocol Attack
15
SQL Injection
14
LFI/Path Traversal
13
Scanner
13
XSS
12
IP atacantes principales
IPEventos
198.51.100.189
198.51.100.227
198.51.100.356
198.51.100.215
198.51.100.135
198.51.100.244
198.51.100.274
198.51.100.154
198.51.100.194
198.51.100.143
Top de URL objetivo
URIEventos
/.env17
/api/v1/login14
/index.php?id=113
/?q=../../etc/passwd11
/admin/11
/wp-login.php11
/xmlrpc.php9
Top de reglas activadas
ID de reglaCoincidencias
930100
Path Traversal (/../)
22
932100
RCE — Unix commands
20
941100
XSS via libinjection
18
942100
SQL Injection via libinjection
14
913100
Security scanner — User-Agent
12
Eventos recientes 86 entradas
HoraIPURITipoReglaAcción
2026-10-11 23:54:38 198.51.100.26 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Detectado
2026-10-11 23:46:26 198.51.100.21 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Bloqueado
2026-10-11 23:39:26 198.51.100.24 /.env XSS 932100
RCE — Unix commands
Detectado
2026-10-11 22:21:17 198.51.100.18 /?q=../../etc/passwd XSS 913100
Security scanner — User-Agent
Bloqueado
2026-10-11 23:30:14 198.51.100.14 /.env XSS 942100
SQL Injection via libinjection
Detectado
2026-10-11 21:28:48 198.51.100.28 /admin/ Scanner 942100
SQL Injection via libinjection
Detectado
2026-10-11 20:46:50 198.51.100.18 /wp-login.php LFI/Path Traversal 932100
RCE — Unix commands
Detectado
2026-10-11 22:08:14 198.51.100.27 /index.php?id=1 LFI/Path Traversal 941100
XSS via libinjection
Detectado
2026-10-11 20:28:30 198.51.100.22 /xmlrpc.php SQL Injection 932100
RCE — Unix commands
Detectado
2026-10-11 20:20:26 198.51.100.12 /api/v1/login RCE 932100
RCE — Unix commands
Detectado
2026-10-11 19:52:48 198.51.100.16 /.env LFI/Path Traversal 932100
RCE — Unix commands
Detectado
2026-10-11 21:17:53 198.51.100.11 /admin/ LFI/Path Traversal 942100
SQL Injection via libinjection
Detectado
2026-10-11 18:49:14 198.51.100.17 /index.php?id=1 Protocol Attack 941100
XSS via libinjection
Bloqueado
2026-10-11 20:45:42 198.51.100.15 /api/v1/login SQL Injection 930100
Path Traversal (/../)
Bloqueado
2026-10-11 17:43:52 198.51.100.18 /api/v1/login Scanner 941100
XSS via libinjection
Detectado
2026-10-11 19:30:08 198.51.100.16 /index.php?id=1 Scanner 941100
XSS via libinjection
Detectado
2026-10-11 17:48:14 198.51.100.22 /.env XSS 932100
RCE — Unix commands
Detectado
2026-10-11 22:00:10 198.51.100.26 /wp-login.php SQL Injection 941100
XSS via libinjection
Detectado
2026-10-11 18:40:14 198.51.100.15 /xmlrpc.php Scanner 913100
Security scanner — User-Agent
Bloqueado
2026-10-11 17:04:52 198.51.100.30 /wp-login.php RCE 941100
XSS via libinjection
Detectado
2026-10-11 18:53:38 198.51.100.35 /index.php?id=1 XSS 941100
XSS via libinjection
Bloqueado
2026-10-11 14:13:38 198.51.100.33 /admin/ Protocol Attack 942100
SQL Injection via libinjection
Detectado
2026-10-11 16:13:00 198.51.100.22 /api/v1/login Protocol Attack 941100
XSS via libinjection
Detectado
2026-10-11 16:52:12 198.51.100.33 /api/v1/login Protocol Attack 942100
SQL Injection via libinjection
Detectado
2026-10-11 18:50:14 198.51.100.18 /wp-login.php RCE 913100
Security scanner — User-Agent
Bloqueado
2026-10-11 11:21:18 198.51.100.33 /?q=../../etc/passwd Protocol Attack 941100
XSS via libinjection
Detectado
2026-10-11 18:56:04 198.51.100.22 /admin/ XSS 942100
SQL Injection via libinjection
Bloqueado
2026-10-11 15:49:32 198.51.100.23 /admin/ Scanner 932100
RCE — Unix commands
Bloqueado
2026-10-11 11:40:06 198.51.100.19 /admin/ RCE 942100
SQL Injection via libinjection
Detectado
2026-10-11 08:49:50 198.51.100.18 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectado
2026-10-11 17:49:38 198.51.100.22 /admin/ SQL Injection 941100
XSS via libinjection
Detectado
2026-10-11 14:31:59 198.51.100.34 /.env LFI/Path Traversal 932100
RCE — Unix commands
Bloqueado
2026-10-11 20:06:54 198.51.100.19 /.env RCE 941100
XSS via libinjection
Detectado
2026-10-11 06:15:20 198.51.100.35 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Detectado
2026-10-11 05:41:32 198.51.100.15 /index.php?id=1 SQL Injection 913100
Security scanner — User-Agent
Detectado
2026-10-11 13:13:33 198.51.100.21 /index.php?id=1 XSS 941100
XSS via libinjection
Detectado
2026-10-11 18:39:02 198.51.100.35 /.env XSS 941100
XSS via libinjection
Detectado
2026-10-11 15:35:45 198.51.100.32 /xmlrpc.php LFI/Path Traversal 930100
Path Traversal (/../)
Bloqueado
2026-10-11 04:29:18 198.51.100.17 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Detectado
2026-10-11 04:31:08 198.51.100.22 /.env Scanner 930100
Path Traversal (/../)
Bloqueado
2026-10-11 06:53:18 198.51.100.24 /api/v1/login RCE 930100
Path Traversal (/../)
Detectado
2026-10-11 13:49:12 198.51.100.25 /xmlrpc.php RCE 932100
RCE — Unix commands
Detectado
2026-10-11 12:51:44 198.51.100.19 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectado
2026-10-11 01:02:56 198.51.100.17 /.env LFI/Path Traversal 913100
Security scanner — User-Agent
Detectado
2026-10-11 15:31:34 198.51.100.21 /.env RCE 930100
Path Traversal (/../)
Detectado
2026-10-11 07:19:23 198.51.100.18 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Bloqueado
2026-10-11 17:20:34 198.51.100.18 /api/v1/login XSS 942100
SQL Injection via libinjection
Detectado
2026-10-11 05:16:49 198.51.100.19 /xmlrpc.php Scanner 930100
Path Traversal (/../)
Detectado
2026-10-11 11:49:50 198.51.100.27 /wp-login.php SQL Injection 932100
RCE — Unix commands
Bloqueado
2026-10-11 11:11:03 198.51.100.18 /.env Scanner 913100
Security scanner — User-Agent
Bloqueado
2026-10-11 17:01:18 198.51.100.24 /.env SQL Injection 913100
Security scanner — User-Agent
Detectado
2026-10-11 02:58:20 198.51.100.12 /?q=../../etc/passwd RCE 941100
XSS via libinjection
Detectado
2026-10-11 04:50:38 198.51.100.27 /admin/ RCE 930100
Path Traversal (/../)
Detectado
2026-10-10 20:18:23 198.51.100.35 /xmlrpc.php RCE 942100
SQL Injection via libinjection
Detectado
2026-10-11 13:11:08 198.51.100.14 /api/v1/login Scanner 930100
Path Traversal (/../)
Detectado
2026-10-10 21:27:53 198.51.100.18 /.env Scanner 941100
XSS via libinjection
Detectado
2026-10-11 05:24:54 198.51.100.20 /api/v1/login RCE 941100
XSS via libinjection
Bloqueado
2026-10-11 04:43:14 198.51.100.13 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Bloqueado
2026-10-11 13:27:16 198.51.100.23 /wp-login.php RCE 941100
XSS via libinjection
Detectado
2026-10-11 05:13:38 198.51.100.11 /wp-login.php XSS 930100
Path Traversal (/../)
Detectado
2026-10-11 18:40:38 198.51.100.31 /?q=../../etc/passwd SQL Injection 913100
Security scanner — User-Agent
Detectado
2026-10-10 15:00:16 198.51.100.21 /api/v1/login Scanner 932100
RCE — Unix commands
Detectado
2026-10-11 02:27:06 198.51.100.29 /xmlrpc.php LFI/Path Traversal 913100
Security scanner — User-Agent
Detectado
2026-10-10 15:27:56 198.51.100.14 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectado
2026-10-10 14:33:34 198.51.100.35 /?q=../../etc/passwd Scanner 930100
Path Traversal (/../)
Bloqueado
2026-10-11 11:39:03 198.51.100.22 /?q=../../etc/passwd SQL Injection 930100
Path Traversal (/../)
Detectado
2026-10-11 17:35:08 198.51.100.24 /wp-login.php RCE 941100
XSS via libinjection
Detectado
2026-10-11 17:30:30 198.51.100.13 /index.php?id=1 LFI/Path Traversal 930100
Path Traversal (/../)
Bloqueado
2026-10-11 12:09:42 198.51.100.21 /index.php?id=1 RCE 930100
Path Traversal (/../)
Detectado
2026-10-10 13:52:14 198.51.100.32 /api/v1/login Scanner 942100
SQL Injection via libinjection
Detectado
2026-10-11 13:35:08 198.51.100.35 /.env Protocol Attack 913100
Security scanner — User-Agent
Detectado
2026-10-11 16:37:59 198.51.100.15 /index.php?id=1 XSS 930100
Path Traversal (/../)
Bloqueado
2026-10-11 11:39:02 198.51.100.25 /?q=../../etc/passwd Protocol Attack 932100
RCE — Unix commands
Detectado
2026-10-11 18:54:07 198.51.100.13 /.env Protocol Attack 932100
RCE — Unix commands
Bloqueado
2026-10-10 10:39:50 198.51.100.11 /api/v1/login LFI/Path Traversal 932100
RCE — Unix commands
Bloqueado
2026-10-11 09:52:08 198.51.100.16 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Bloqueado
2026-10-10 19:15:46 198.51.100.34 /admin/ SQL Injection 932100
RCE — Unix commands
Detectado
2026-10-10 20:40:57 198.51.100.28 /.env RCE 932100
RCE — Unix commands
Bloqueado
2026-10-11 04:09:02 198.51.100.13 /admin/ Protocol Attack 930100
Path Traversal (/../)
Detectado
2026-10-11 15:55:22 198.51.100.25 /admin/ SQL Injection 932100
RCE — Unix commands
Detectado
2026-10-10 15:17:18 198.51.100.28 /api/v1/login RCE 942100
SQL Injection via libinjection
Bloqueado
2026-10-10 10:33:38 198.51.100.30 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Detectado
2026-10-10 16:43:40 198.51.100.27 /.env SQL Injection 930100
Path Traversal (/../)
Detectado
2026-10-11 05:59:47 198.51.100.20 /index.php?id=1 LFI/Path Traversal 942100
SQL Injection via libinjection
Detectado
2026-10-11 10:36:38 198.51.100.13 /index.php?id=1 Protocol Attack 930100
Path Traversal (/../)
Detectado
2026-10-11 11:12:28 198.51.100.31 /api/v1/login XSS 930100
Path Traversal (/../)
Bloqueado

Un ModSecurity log viewer para el registro de auditoría

ModSecurity con el OWASP Core Rule Set bloquea muchísimo, y escribe sobre casi todo ello en un registro de auditoría con un formato pensado para máquinas. Esta página lo convierte en algo legible: qué peticiones se bloquearon, qué regla se disparó, cuál fue la puntuación de anomalía y de dónde venía la petición.

El motivo para mirar aquí con regularidad son los falsos positivos. El Core Rule Set es deliberadamente estricto y, con el nivel de paranoia por defecto, bloqueará tráfico legítimo en la mayoría de aplicaciones reales: las subidas de archivos, los editores de texto enriquecido y todo lo que envíe marcado o cadenas parecidas a SQL son las víctimas habituales. El patrón a detectar es el mismo identificador de regla disparándose una y otra vez contra el mismo endpoint desde muchas direcciones distintas. Eso no es un ataque: es su propia aplicación siendo atrapada.

Cuando lo encuentre, ponga la excepción estrecha: excluya esa regla concreta para ese parámetro concreto en esa ruta concreta, no la regla entera y desde luego no la categoría completa. La página también lista el conjunto de reglas activo, para confirmar qué está cargado realmente tras un cambio.