| IP | אירועים |
|---|---|
198.51.100.31 | 6 |
198.51.100.23 | 6 |
198.51.100.14 | 4 |
198.51.100.35 | 4 |
198.51.100.24 | 4 |
198.51.100.17 | 4 |
198.51.100.12 | 4 |
198.51.100.13 | 4 |
198.51.100.33 | 4 |
198.51.100.28 | 4 |
| URI | אירועים |
|---|---|
/.env | 16 |
/index.php?id=1 | 13 |
/api/v1/login | 12 |
/wp-login.php | 12 |
/admin/ | 9 |
/xmlrpc.php | 8 |
/?q=../../etc/passwd | 7 |
| מזהה כלל | הפעלות |
|---|---|
930100Path Traversal (/../) |
20 |
913100Security scanner — User-Agent |
17 |
932100RCE — Unix commands |
16 |
941100XSS via libinjection |
12 |
942100SQL Injection via libinjection |
12 |
| זמן | IP | URI | סוג | כלל | פעולה |
|---|---|---|---|---|---|
| 2026-10-12 01:03:00 | 198.51.100.14 |
/admin/ |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
נחסם |
| 2026-10-12 00:48:33 | 198.51.100.20 |
/api/v1/login |
Protocol Attack | 932100 RCE — Unix commands |
נחסם |
| 2026-10-12 00:52:08 | 198.51.100.35 |
/.env |
Protocol Attack | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 23:44:27 | 198.51.100.24 |
/wp-login.php |
XSS | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 23:07:12 | 198.51.100.29 |
/?q=../../etc/passwd |
SQL Injection | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 22:59:00 | 198.51.100.31 |
/index.php?id=1 |
SQL Injection | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 23:46:12 | 198.51.100.16 |
/index.php?id=1 |
SQL Injection | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 21:27:31 | 198.51.100.11 |
/.env |
Protocol Attack | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 22:39:32 | 198.51.100.17 |
/.env |
RCE | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 20:44:33 | 198.51.100.15 |
/api/v1/login |
XSS | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 22:55:10 | 198.51.100.12 |
/index.php?id=1 |
XSS | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 19:27:19 | 198.51.100.26 |
/wp-login.php |
RCE | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 19:07:00 | 198.51.100.13 |
/index.php?id=1 |
XSS | 932100 RCE — Unix commands |
נחסם |
| 2026-10-11 21:38:54 | 198.51.100.35 |
/admin/ |
LFI/Path Traversal | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 18:44:04 | 198.51.100.23 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-12 00:00:00 | 198.51.100.13 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 22:20:36 | 198.51.100.23 |
/admin/ |
SQL Injection | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 19:12:48 | 198.51.100.34 |
/.env |
LFI/Path Traversal | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 21:04:12 | 198.51.100.33 |
/wp-login.php |
SQL Injection | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 18:07:51 | 198.51.100.28 |
/api/v1/login |
LFI/Path Traversal | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 20:20:00 | 198.51.100.23 |
/.env |
Scanner | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 23:19:03 | 198.51.100.30 |
/admin/ |
SQL Injection | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 14:43:42 | 198.51.100.23 |
/xmlrpc.php |
Protocol Attack | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 18:47:20 | 198.51.100.24 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 15:45:00 | 198.51.100.11 |
/api/v1/login |
Protocol Attack | 913100 Security scanner — User-Agent |
נחסם |
| 2026-10-11 18:35:55 | 198.51.100.19 |
/api/v1/login |
Scanner | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 13:01:56 | 198.51.100.18 |
/index.php?id=1 |
RCE | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 16:25:03 | 198.51.100.32 |
/.env |
SQL Injection | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 23:18:28 | 198.51.100.14 |
/api/v1/login |
RCE | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 10:26:14 | 198.51.100.28 |
/xmlrpc.php |
Protocol Attack | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 16:19:30 | 198.51.100.30 |
/.env |
RCE | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 20:40:01 | 198.51.100.33 |
/.env |
SQL Injection | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-11 18:08:36 | 198.51.100.16 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 19:45:39 | 198.51.100.16 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-11 07:38:04 | 198.51.100.18 |
/.env |
LFI/Path Traversal | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 13:17:10 | 198.51.100.28 |
/api/v1/login |
Protocol Attack | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 13:02:24 | 198.51.100.31 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
נחסם |
| 2026-10-11 10:19:56 | 198.51.100.17 |
/xmlrpc.php |
Scanner | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 13:54:50 | 198.51.100.29 |
/.env |
RCE | 913100 Security scanner — User-Agent |
נחסם |
| 2026-10-11 20:57:57 | 198.51.100.18 |
/?q=../../etc/passwd |
RCE | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-11 20:15:00 | 198.51.100.35 |
/admin/ |
Protocol Attack | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-11 15:18:04 | 198.51.100.26 |
/.env |
LFI/Path Traversal | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 12:13:00 | 198.51.100.13 |
/admin/ |
Protocol Attack | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 07:08:43 | 198.51.100.29 |
/xmlrpc.php |
XSS | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 09:37:32 | 198.51.100.12 |
/index.php?id=1 |
Scanner | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 05:10:30 | 198.51.100.15 |
/index.php?id=1 |
LFI/Path Traversal | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-11 17:45:14 | 198.51.100.13 |
/?q=../../etc/passwd |
Protocol Attack | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 21:32:17 | 198.51.100.12 |
/.env |
SQL Injection | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 15:15:48 | 198.51.100.25 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 14:31:43 | 198.51.100.33 |
/wp-login.php |
XSS | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 06:28:00 | 198.51.100.22 |
/admin/ |
RCE | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 19:00:03 | 198.51.100.32 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
נחסם |
| 2026-10-11 16:49:00 | 198.51.100.31 |
/.env |
XSS | 932100 RCE — Unix commands |
נחסם |
| 2026-10-11 07:30:57 | 198.51.100.19 |
/xmlrpc.php |
SQL Injection | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 01:40:48 | 198.51.100.31 |
/index.php?id=1 |
Scanner | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 08:33:55 | 198.51.100.23 |
/admin/ |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 11:07:40 | 198.51.100.30 |
/wp-login.php |
Scanner | 941100 XSS via libinjection |
זוהה |
| 2026-10-10 23:00:15 | 198.51.100.24 |
/?q=../../etc/passwd |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
נחסם |
| 2026-10-11 05:56:32 | 198.51.100.18 |
/index.php?id=1 |
Scanner | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-10 23:14:15 | 198.51.100.25 |
/wp-login.php |
Scanner | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 16:56:00 | 198.51.100.17 |
/.env |
XSS | 930100 Path Traversal (/../) |
נחסם |
| 2026-10-10 21:27:52 | 198.51.100.32 |
/wp-login.php |
SQL Injection | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 05:31:12 | 198.51.100.23 |
/index.php?id=1 |
XSS | 942100 SQL Injection via libinjection |
זוהה |
| 2026-10-11 05:10:12 | 198.51.100.22 |
/index.php?id=1 |
XSS | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-10 22:57:08 | 198.51.100.26 |
/admin/ |
SQL Injection | 942100 SQL Injection via libinjection |
נחסם |
| 2026-10-11 09:34:35 | 198.51.100.24 |
/api/v1/login |
SQL Injection | 913100 Security scanner — User-Agent |
נחסם |
| 2026-10-11 18:09:24 | 198.51.100.17 |
/.env |
Scanner | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 08:53:44 | 198.51.100.19 |
/wp-login.php |
XSS | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 06:19:52 | 198.51.100.14 |
/api/v1/login |
Protocol Attack | 932100 RCE — Unix commands |
זוהה |
| 2026-10-11 03:35:00 | 198.51.100.21 |
/?q=../../etc/passwd |
SQL Injection | 932100 RCE — Unix commands |
נחסם |
| 2026-10-10 22:13:00 | 198.51.100.31 |
/index.php?id=1 |
XSS | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 17:38:04 | 198.51.100.14 |
/?q=../../etc/passwd |
Scanner | 932100 RCE — Unix commands |
נחסם |
| 2026-10-11 15:30:36 | 198.51.100.28 |
/wp-login.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
זוהה |
| 2026-10-11 11:14:27 | 198.51.100.35 |
/xmlrpc.php |
Protocol Attack | 941100 XSS via libinjection |
נחסם |
| 2026-10-11 13:55:46 | 198.51.100.31 |
/.env |
RCE | 941100 XSS via libinjection |
זוהה |
| 2026-10-11 13:14:15 | 198.51.100.33 |
/api/v1/login |
RCE | 913100 Security scanner — User-Agent |
זוהה |
| 2026-10-11 16:33:48 | 198.51.100.12 |
/wp-login.php |
SQL Injection | 942100 SQL Injection via libinjection |
זוהה |
ModSecurity עם OWASP Core Rule Set חוסם המון, וכותב על כמעט כל זה ליומן ביקורת שתבניתו נועדה למכונות. הדף הופך אותו לדבר קריא: אילו בקשות נחסמו, איזה כלל נורה, מה היה ציון החריגה ומאין הגיעה הבקשה.
הסיבה להציץ לכאן באופן קבוע היא התרעות שווא. מערך הכללים המרכזי מחמיר במתכוון, וברמת הפרנויה שבברירת המחדל הוא חוסם תעבורה לגיטימית ברוב היישומים האמיתיים: העלאת קבצים, עורכי טקסט מעוצב וכל מה ששולח תגיות או מחרוזות הדומות ל-SQL הם הקורבנות הרגילים. התבנית שיש לזהות היא אותו מזהה כלל שנורה שוב ושוב על אותה נקודת קצה ממספר רב של כתובות שונות. זו אינה מתקפה, זה היישום שלכם שנתפס.
כשמוצאים מקרה כזה, שמרו על חריג צר: הוציאו מכלל תחולה את אותו כלל בדיוק, עבור אותו פרמטר בדיוק, באותו נתיב בדיוק — לעולם לא את הכלל כולו, ובוודאי לא את הקטגוריה כולה. הדף מפרט גם את מערך הכללים הפעיל, כדי שתאשרו לאחר שינוי מה באמת טעון.