| ID aturan | Kategori | Pesan | Pemicuan |
|---|---|---|---|
901001 |
Initialization | ModSecurity Core Rule Set is deployed without configuration! Please copy the crs-setup.conf.example template to crs-setup.conf, and include the crs-setup.conf file in your webserver configuration before including the CRS rules. See the INSTALL file in the CRS directory for detailed instructions | — |
901100 |
Initialization | — | — |
901110 |
Initialization | — | — |
901120 |
Initialization | — | — |
901125 |
Initialization | — | — |
901130 |
Initialization | — | — |
901140 |
Initialization | — | — |
901141 |
Initialization | — | — |
901142 |
Initialization | — | — |
901143 |
Initialization | — | — |
901150 |
Initialization | — | — |
901152 |
Initialization | — | — |
901160 |
Initialization | — | — |
901162 |
Initialization | — | — |
901163 |
Initialization | — | — |
901164 |
Initialization | — | — |
901165 |
Initialization | — | — |
901166 |
Initialization | — | — |
901167 |
Initialization | — | — |
901168 |
Initialization | — | — |
901200 |
Initialization | — | — |
901318 |
Initialization | — | — |
901321 |
Initialization | — | — |
901340 |
Initialization | Enabling body inspection | — |
901350 |
Initialization | Enabling forced body inspection for ASCII content | — |
901400 |
Initialization | — | — |
901410 |
Initialization | — | — |
901420 |
Initialization | — | — |
901430 |
Initialization | — | — |
901440 |
Initialization | — | — |
901450 |
Initialization | Sampling: Disable the rule engine based on sampling_percentage %{TX.sampling_percentage} and random number %{TX.sampling_rnd100} | — |
901500 |
Initialization | Executing paranoia level configured is lower than the paranoia level itself. This is illegal. Blocking request. Aborting | — |
905100 |
Common Exceptions | — | — |
905110 |
Common Exceptions | — | — |
910000 |
Ip Reputation | Request from Known Malicious Client (Based on previous traffic violations) | — |
910011 |
Ip Reputation | — | — |
910012 |
Ip Reputation | — | — |
910013 |
Ip Reputation | — | — |
910014 |
Ip Reputation | — | — |
910015 |
Ip Reputation | — | — |
910016 |
Ip Reputation | — | — |
910017 |
Ip Reputation | — | — |
910018 |
Ip Reputation | — | — |
910100 |
Ip Reputation | Client IP is from a HIGH Risk Country Location | — |
910110 |
Ip Reputation | Client IP in Trustwave SpiderLabs IP Reputation Blacklist | — |
910120 |
Ip Reputation | — | — |
910130 |
Ip Reputation | — | — |
910140 |
Ip Reputation | — | — |
910150 |
Ip Reputation | HTTP Blacklist match for search engine IP | — |
910160 |
Ip Reputation | HTTP Blacklist match for spammer IP | — |
910170 |
Ip Reputation | HTTP Blacklist match for suspicious IP | — |
910180 |
Ip Reputation | HTTP Blacklist match for harvester IP | — |
910190 |
Ip Reputation | — | — |
911011 |
Method Enforcement | — | — |
911012 |
Method Enforcement | — | — |
911013 |
Method Enforcement | — | — |
911014 |
Method Enforcement | — | — |
911015 |
Method Enforcement | — | — |
911016 |
Method Enforcement | — | — |
911017 |
Method Enforcement | — | — |
911018 |
Method Enforcement | — | — |
911100 |
Method Enforcement | Method is not allowed by policy | — |
912011 |
Dos Protection | — | — |
912012 |
Dos Protection | — | — |
912013 |
Dos Protection | — | — |
912014 |
Dos Protection | — | — |
912015 |
Dos Protection | — | — |
912016 |
Dos Protection | — | — |
912017 |
Dos Protection | — | — |
912018 |
Dos Protection | — | — |
912019 |
Dos Protection | — | — |
912100 |
Dos Protection | — | — |
912110 |
Dos Protection | — | — |
912120 |
Dos Protection | Denial of Service (DoS) attack identified from %{tx.real_ip} (%{tx.dos_block_counter} hits since last alert) | — |
912130 |
Dos Protection | — | — |
912140 |
Dos Protection | — | — |
912150 |
Dos Protection | — | — |
912160 |
Dos Protection | — | — |
912161 |
Dos Protection | — | — |
912170 |
Dos Protection | Potential Denial of Service (DoS) Attack from %{tx.real_ip} - # of Request Bursts: %{ip.dos_burst_counter} | — |
912171 |
Dos Protection | Potential Denial of Service (DoS) Attack from %{tx.real_ip} - # of Request Bursts: %{ip.dos_burst_counter} | — |
913011 |
Scanner Detection | — | — |
913012 |
Scanner Detection | — | — |
913013 |
Scanner Detection | — | — |
913014 |
Scanner Detection | — | — |
913015 |
Scanner Detection | — | — |
913016 |
Scanner Detection | — | — |
913017 |
Scanner Detection | — | — |
913018 |
Scanner Detection | — | — |
913100 |
Scanner Detection | Found User-Agent associated with security scanner | 9 |
913101 |
Scanner Detection | Found User-Agent associated with scripting/generic HTTP client | — |
913102 |
Scanner Detection | Found User-Agent associated with web crawler/bot | — |
913110 |
Scanner Detection | Found request header associated with security scanner | — |
913120 |
Scanner Detection | Found request filename/argument associated with security scanner | — |
920011 |
Protocol Enforcement | — | — |
920012 |
Protocol Enforcement | — | — |
920013 |
Protocol Enforcement | — | — |
920014 |
Protocol Enforcement | — | — |
920015 |
Protocol Enforcement | — | — |
920016 |
Protocol Enforcement | — | — |
920017 |
Protocol Enforcement | — | — |
920018 |
Protocol Enforcement | — | — |
920100 |
Protocol Enforcement | Invalid HTTP Request Line | — |
920120 |
Protocol Enforcement | Attempted multipart/form-data bypass | — |
920121 |
Protocol Enforcement | Attempted multipart/form-data bypass | — |
920160 |
Protocol Enforcement | Content-Length HTTP header is not numeric | — |
920170 |
Protocol Enforcement | GET or HEAD Request with Body Content | — |
920171 |
Protocol Enforcement | GET or HEAD Request with Transfer-Encoding | — |
920180 |
Protocol Enforcement | POST without Content-Length or Transfer-Encoding headers | — |
920181 |
Protocol Enforcement | Content-Length and Transfer-Encoding headers present. | — |
920190 |
Protocol Enforcement | Range: Invalid Last Byte Value | — |
920200 |
Protocol Enforcement | Range: Too many fields (6 or more) | — |
920201 |
Protocol Enforcement | Range: Too many fields for pdf request (63 or more) | — |
920202 |
Protocol Enforcement | Range: Too many fields for pdf request (6 or more) | — |
920210 |
Protocol Enforcement | Multiple/Conflicting Connection Header Data Found | — |
920220 |
Protocol Enforcement | URL Encoding Abuse Attack Attempt | — |
920230 |
Protocol Enforcement | Multiple URL Encoding Detected | — |
920240 |
Protocol Enforcement | URL Encoding Abuse Attack Attempt | — |
920250 |
Protocol Enforcement | UTF8 Encoding Abuse Attack Attempt | — |
920260 |
Protocol Enforcement | Unicode Full/Half Width Abuse Attack Attempt | — |
920270 |
Protocol Enforcement | Invalid character in request (null character) | — |
920271 |
Protocol Enforcement | Invalid character in request (non printable characters) | — |
920272 |
Protocol Enforcement | Invalid character in request (outside of printable chars below ascii 127) | — |
920273 |
Protocol Enforcement | Invalid character in request (outside of very strict set) | — |
920274 |
Protocol Enforcement | Invalid character in request headers (outside of very strict set) | — |
920275 |
Protocol Enforcement | Invalid character in request headers (outside of very strict set) | — |
920280 |
Protocol Enforcement | Request Missing a Host Header | — |
920290 |
Protocol Enforcement | Empty Host Header | — |
920300 |
Protocol Enforcement | Request Missing an Accept Header | — |
920310 |
Protocol Enforcement | Request Has an Empty Accept Header | — |
920311 |
Protocol Enforcement | Request Has an Empty Accept Header | — |
920320 |
Protocol Enforcement | Missing User Agent Header | — |
920330 |
Protocol Enforcement | Empty User Agent Header | — |
920340 |
Protocol Enforcement | Request Containing Content, but Missing Content-Type header | — |
920341 |
Protocol Enforcement | Request Containing Content Requires Content-Type header | — |
920350 |
Protocol Enforcement | Host header is a numeric IP address | — |
920360 |
Protocol Enforcement | Argument name too long | — |
920370 |
Protocol Enforcement | Argument value too long | — |
920380 |
Protocol Enforcement | Too many arguments in request | — |
920390 |
Protocol Enforcement | Total arguments size exceeded | — |
920400 |
Protocol Enforcement | Uploaded file size too large | — |
920410 |
Protocol Enforcement | Total uploaded files size too large | — |
920420 |
Protocol Enforcement | Request content type is not allowed by policy | — |
920430 |
Protocol Enforcement | HTTP protocol version is not allowed by policy | — |
920440 |
Protocol Enforcement | URL file extension is restricted by policy | — |
920450 |
Protocol Enforcement | HTTP header is restricted by policy (%{MATCHED_VAR}) | — |
920460 |
Protocol Enforcement | Abnormal character escapes in request | — |
920470 |
Protocol Enforcement | Illegal Content-Type header | — |
920480 |
Protocol Enforcement | Request content type charset is not allowed by policy | — |
920490 |
Protocol Enforcement | Request header x-up-devcap-post-charset detected in combination with prefix \ | — |
920500 |
Protocol Enforcement | Attempt to access a backup or working file | — |
920510 |
Protocol Enforcement | Invalid Cache-Control request header | — |
921011 |
Protocol Attack | — | — |
921012 |
Protocol Attack | — | — |
921013 |
Protocol Attack | — | — |
921014 |
Protocol Attack | — | — |
921015 |
Protocol Attack | — | — |
921016 |
Protocol Attack | — | — |
921017 |
Protocol Attack | — | — |
921018 |
Protocol Attack | — | — |
921110 |
Protocol Attack | HTTP Request Smuggling Attack | — |
921120 |
Protocol Attack | HTTP Response Splitting Attack | — |
921130 |
Protocol Attack | HTTP Response Splitting Attack | — |
921140 |
Protocol Attack | HTTP Header Injection Attack via headers | — |
921150 |
Protocol Attack | HTTP Header Injection Attack via payload (CR/LF detected) | — |
921151 |
Protocol Attack | HTTP Header Injection Attack via payload (CR/LF detected) | — |
921160 |
Protocol Attack | HTTP Header Injection Attack via payload (CR/LF and header-name detected) | — |
921170 |
Protocol Attack | — | — |
921180 |
Protocol Attack | HTTP Parameter Pollution (%{TX.1}) | — |
921190 |
Protocol Attack | HTTP Splitting (CR/LF in request filename detected) | — |
921200 |
Protocol Attack | LDAP Injection Attack | — |
930011 |
Application Attack Lfi | — | — |
930012 |
Application Attack Lfi | — | — |
930013 |
Application Attack Lfi | — | — |
930014 |
Application Attack Lfi | — | — |
930015 |
Application Attack Lfi | — | — |
930016 |
Application Attack Lfi | — | — |
930017 |
Application Attack Lfi | — | — |
930018 |
Application Attack Lfi | — | — |
930100 |
Application Attack Lfi | Path Traversal Attack (/../) | 11 |
930110 |
Application Attack Lfi | Path Traversal Attack (/../) | — |
930120 |
Application Attack Lfi | OS File Access Attempt | — |
930130 |
Application Attack Lfi | Restricted File Access Attempt | — |
931011 |
Application Attack Rfi | — | — |
931012 |
Application Attack Rfi | — | — |
931013 |
Application Attack Rfi | — | — |
931014 |
Application Attack Rfi | — | — |
931015 |
Application Attack Rfi | — | — |
931016 |
Application Attack Rfi | — | — |
931017 |
Application Attack Rfi | — | — |
931018 |
Application Attack Rfi | — | — |
931100 |
Application Attack Rfi | Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address | — |
931110 |
Application Attack Rfi | Possible Remote File Inclusion (RFI) Attack: Common RFI Vulnerable Parameter Name used w/URL Payload | — |
931120 |
Application Attack Rfi | Possible Remote File Inclusion (RFI) Attack: URL Payload Used w/Trailing Question Mark Character (?) | — |
931130 |
Application Attack Rfi | Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link | — |
932011 |
Application Attack Rce | — | — |
932012 |
Application Attack Rce | — | — |
932013 |
Application Attack Rce | — | — |
932014 |
Application Attack Rce | — | — |
932015 |
Application Attack Rce | — | — |
932016 |
Application Attack Rce | — | — |
932017 |
Application Attack Rce | — | — |
932018 |
Application Attack Rce | — | — |
932100 |
Application Attack Rce | Remote Command Execution: Unix Command Injection | 9 |
932105 |
Application Attack Rce | Remote Command Execution: Unix Command Injection | — |
932106 |
Application Attack Rce | Remote Command Execution: Unix Command Injection | — |
932110 |
Application Attack Rce | Remote Command Execution: Windows Command Injection | — |
932115 |
Application Attack Rce | Remote Command Execution: Windows Command Injection | — |
932120 |
Application Attack Rce | Remote Command Execution: Windows PowerShell Command Found | — |
932130 |
Application Attack Rce | Remote Command Execution: Unix Shell Expression Found | — |
932140 |
Application Attack Rce | Remote Command Execution: Windows FOR/IF Command Found | — |
932150 |
Application Attack Rce | Remote Command Execution: Direct Unix Command Execution | — |
932160 |
Application Attack Rce | Remote Command Execution: Unix Shell Code Found | — |
932170 |
Application Attack Rce | Remote Command Execution: Shellshock (CVE-2014-6271) | — |
932171 |
Application Attack Rce | Remote Command Execution: Shellshock (CVE-2014-6271) | — |
932180 |
Application Attack Rce | Restricted File Upload Attempt | — |
932190 |
Application Attack Rce | Remote Command Execution: Wildcard bypass technique attempt | — |
932200 |
Application Attack Rce | RCE Bypass Technique | — |
933011 |
Application Attack Php | — | — |
933012 |
Application Attack Php | — | — |
933013 |
Application Attack Php | — | — |
933014 |
Application Attack Php | — | — |
933015 |
Application Attack Php | — | — |
933016 |
Application Attack Php | — | — |
933017 |
Application Attack Php | — | — |
933018 |
Application Attack Php | — | — |
933100 |
Application Attack Php | PHP Injection Attack: PHP Open Tag Found | — |
933110 |
Application Attack Php | PHP Injection Attack: PHP Script File Upload Found | — |
933111 |
Application Attack Php | PHP Injection Attack: PHP Script File Upload Found | — |
933120 |
Application Attack Php | PHP Injection Attack: Configuration Directive Found | — |
933130 |
Application Attack Php | PHP Injection Attack: Variables Found | — |
933131 |
Application Attack Php | PHP Injection Attack: Variables Found | — |
933140 |
Application Attack Php | PHP Injection Attack: I/O Stream Found | — |
933150 |
Application Attack Php | PHP Injection Attack: High-Risk PHP Function Name Found | — |
933151 |
Application Attack Php | PHP Injection Attack: Medium-Risk PHP Function Name Found | — |
933160 |
Application Attack Php | PHP Injection Attack: High-Risk PHP Function Call Found | — |
933161 |
Application Attack Php | PHP Injection Attack: Low-Value PHP Function Call Found | — |
933170 |
Application Attack Php | PHP Injection Attack: Serialized Object Injection | — |
933180 |
Application Attack Php | PHP Injection Attack: Variable Function Call Found | — |
933190 |
Application Attack Php | PHP Injection Attack: PHP Closing Tag Found | — |
933200 |
Application Attack Php | PHP Injection Attack: Wrapper scheme detected | — |
933210 |
Application Attack Php | PHP Injection Attack: Variable Function Call Found | — |
934011 |
Application Attack Nodejs | — | — |
934012 |
Application Attack Nodejs | — | — |
934013 |
Application Attack Nodejs | — | — |
934014 |
Application Attack Nodejs | — | — |
934015 |
Application Attack Nodejs | — | — |
934016 |
Application Attack Nodejs | — | — |
934017 |
Application Attack Nodejs | — | — |
934018 |
Application Attack Nodejs | — | — |
934100 |
Application Attack Nodejs | Node.js Injection Attack | — |
941011 |
Application Attack Xss | — | — |
941012 |
Application Attack Xss | — | — |
941013 |
Application Attack Xss | — | — |
941014 |
Application Attack Xss | — | — |
941015 |
Application Attack Xss | — | — |
941016 |
Application Attack Xss | — | — |
941017 |
Application Attack Xss | — | — |
941018 |
Application Attack Xss | — | — |
941100 |
Application Attack Xss | XSS Attack Detected via libinjection | 3 |
941101 |
Application Attack Xss | XSS Attack Detected via libinjection | — |
941110 |
Application Attack Xss | XSS Filter - Category 1: Script Tag Vector | — |
941120 |
Application Attack Xss | XSS Filter - Category 2: Event Handler Vector | — |
941130 |
Application Attack Xss | XSS Filter - Category 3: Attribute Vector | — |
941140 |
Application Attack Xss | XSS Filter - Category 4: Javascript URI Vector | — |
941150 |
Application Attack Xss | XSS Filter - Category 5: Disallowed HTML Attributes | — |
941160 |
Application Attack Xss | NoScript XSS InjectionChecker: HTML Injection | — |
941170 |
Application Attack Xss | NoScript XSS InjectionChecker: Attribute Injection | — |
941180 |
Application Attack Xss | Node-Validator Blacklist Keywords | — |
941190 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941200 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941210 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941220 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941230 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941240 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941250 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941260 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941270 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941280 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941290 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941300 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941310 |
Application Attack Xss | US-ASCII Malformed Encoding XSS Filter - Attack Detected | — |
941320 |
Application Attack Xss | Possible XSS Attack Detected - HTML Tag Handler | — |
941330 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941340 |
Application Attack Xss | IE XSS Filters - Attack Detected | — |
941350 |
Application Attack Xss | UTF-7 Encoding IE XSS - Attack Detected | — |
941360 |
Application Attack Xss | JSFuck / Hieroglyphy obfuscation detected | — |
941370 |
Application Attack Xss | JavaScript global variable found | — |
941380 |
Application Attack Xss | AngularJS client side template injection detected | — |
942011 |
Application Attack Sqli | — | — |
942012 |
Application Attack Sqli | — | — |
942013 |
Application Attack Sqli | — | — |
942014 |
Application Attack Sqli | — | — |
942015 |
Application Attack Sqli | — | — |
942016 |
Application Attack Sqli | — | — |
942017 |
Application Attack Sqli | — | — |
942018 |
Application Attack Sqli | — | — |
942100 |
Application Attack Sqli | SQL Injection Attack Detected via libinjection | 11 |
942101 |
Application Attack Sqli | SQL Injection Attack Detected via libinjection | — |
942110 |
Application Attack Sqli | SQL Injection Attack: Common Injection Testing Detected | — |
942120 |
Application Attack Sqli | SQL Injection Attack: SQL Operator Detected | — |
942130 |
Application Attack Sqli | SQL Injection Attack: SQL Tautology Detected | — |
942140 |
Application Attack Sqli | SQL Injection Attack: Common DB Names Detected | — |
942150 |
Application Attack Sqli | SQL Injection Attack | — |
942160 |
Application Attack Sqli | Detects blind sqli tests using sleep() or benchmark() | — |
942170 |
Application Attack Sqli | Detects SQL benchmark and sleep injection attempts including conditional queries | — |
942180 |
Application Attack Sqli | Detects basic SQL authentication bypass attempts 1/3 | — |
942190 |
Application Attack Sqli | Detects MSSQL code execution and information gathering attempts | — |
942200 |
Application Attack Sqli | Detects MySQL comment-/space-obfuscated injections and backtick termination | — |
942210 |
Application Attack Sqli | Detects chained SQL injection attempts 1/2 | — |
942220 |
Application Attack Sqli | Looking for integer overflow attacks, these are taken from skipfish, except 3.0.00738585072007e-308 is the \"magic number\" crash | — |
942230 |
Application Attack Sqli | Detects conditional SQL injection attempts | — |
942240 |
Application Attack Sqli | Detects MySQL charset switch and MSSQL DoS attempts | — |
942250 |
Application Attack Sqli | Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections | — |
942251 |
Application Attack Sqli | Detects HAVING injections | — |
942260 |
Application Attack Sqli | Detects basic SQL authentication bypass attempts 2/3 | — |
942270 |
Application Attack Sqli | Looking for basic sql injection. Common attack string for mysql, oracle and others | — |
942280 |
Application Attack Sqli | Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts | — |
942290 |
Application Attack Sqli | Finds basic MongoDB SQL injection attempts | — |
942300 |
Application Attack Sqli | Detects MySQL comments, conditions and ch(a)r injections | — |
942310 |
Application Attack Sqli | Detects chained SQL injection attempts 2/2 | — |
942320 |
Application Attack Sqli | Detects MySQL and PostgreSQL stored procedure/function injections | — |
942330 |
Application Attack Sqli | Detects classic SQL injection probings 1/3 | — |
942340 |
Application Attack Sqli | Detects basic SQL authentication bypass attempts 3/3 | — |
942350 |
Application Attack Sqli | Detects MySQL UDF injection and other data/structure manipulation attempts | — |
942360 |
Application Attack Sqli | Detects concatenated basic SQL injection and SQLLFI attempts | — |
942361 |
Application Attack Sqli | Detects basic SQL injection based on keyword alter or union | — |
942370 |
Application Attack Sqli | Detects classic SQL injection probings 2/3 | — |
942380 |
Application Attack Sqli | SQL Injection Attack | — |
942390 |
Application Attack Sqli | SQL Injection Attack | — |
942400 |
Application Attack Sqli | SQL Injection Attack | — |
942410 |
Application Attack Sqli | SQL Injection Attack | — |
942420 |
Application Attack Sqli | Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (8) | — |
942421 |
Application Attack Sqli | Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3) | — |
942430 |
Application Attack Sqli | Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (12) | — |
942431 |
Application Attack Sqli | Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) | — |
942432 |
Application Attack Sqli | Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) | — |
942440 |
Application Attack Sqli | SQL Comment Sequence Detected | — |
942450 |
Application Attack Sqli | SQL Hex Encoding Identified | — |
942460 |
Application Attack Sqli | Meta-Character Anomaly Detection Alert - Repetitive Non-Word Characters | — |
942470 |
Application Attack Sqli | SQL Injection Attack | — |
942480 |
Application Attack Sqli | SQL Injection Attack | — |
942490 |
Application Attack Sqli | Detects classic SQL injection probings 3/3 | — |
942500 |
Application Attack Sqli | MySQL in-line comment detected | — |
942510 |
Application Attack Sqli | SQLi bypass attempt by ticks or backticks detected | — |
942511 |
Application Attack Sqli | SQLi bypass attempt by ticks detected | — |
943011 |
Application Attack Session Fixation | — | — |
943012 |
Application Attack Session Fixation | — | — |
943013 |
Application Attack Session Fixation | — | — |
943014 |
Application Attack Session Fixation | — | — |
943015 |
Application Attack Session Fixation | — | — |
943016 |
Application Attack Session Fixation | — | — |
943017 |
Application Attack Session Fixation | — | — |
943018 |
Application Attack Session Fixation | — | — |
943100 |
Application Attack Session Fixation | Possible Session Fixation Attack: Setting Cookie Values in HTML | — |
943110 |
Application Attack Session Fixation | Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer | — |
943120 |
Application Attack Session Fixation | Possible Session Fixation Attack: SessionID Parameter Name with No Referer | — |
944011 |
Application Attack Java | — | — |
944012 |
Application Attack Java | — | — |
944013 |
Application Attack Java | — | — |
944014 |
Application Attack Java | — | — |
944015 |
Application Attack Java | — | — |
944016 |
Application Attack Java | — | — |
944017 |
Application Attack Java | — | — |
944018 |
Application Attack Java | — | — |
944100 |
Application Attack Java | Remote Command Execution: Suspicious Java class detected | — |
944110 |
Application Attack Java | Remote Command Execution: Java process spawn (CVE-2017-9805) | — |
944120 |
Application Attack Java | Remote Command Execution: Java serialization (CVE-2015-4852) | — |
944130 |
Application Attack Java | Suspicious Java class detected | — |
944200 |
Application Attack Java | Magic bytes Detected, probable java serialization in use | — |
944210 |
Application Attack Java | Magic bytes Detected Base64 Encoded, probable java serialization in use | — |
944240 |
Application Attack Java | Remote Command Execution: Java serialization (CVE-2015-4852) | — |
944250 |
Application Attack Java | Remote Command Execution: Suspicious Java method detected | — |
944300 |
Application Attack Java | Base64 encoded string matched suspicious keyword | — |
949011 |
Blocking Evaluation | — | — |
949012 |
Blocking Evaluation | — | — |
949013 |
Blocking Evaluation | — | — |
949014 |
Blocking Evaluation | — | — |
949015 |
Blocking Evaluation | — | — |
949016 |
Blocking Evaluation | — | — |
949017 |
Blocking Evaluation | — | — |
949018 |
Blocking Evaluation | — | — |
949060 |
Blocking Evaluation | — | — |
949061 |
Blocking Evaluation | — | — |
949062 |
Blocking Evaluation | — | — |
949063 |
Blocking Evaluation | — | — |
949100 |
Blocking Evaluation | Request Denied by IP Reputation Enforcement | — |
949110 |
Blocking Evaluation | Inbound Anomaly Score Exceeded (Total Score: %{TX.ANOMALY_SCORE}) | — |
950013 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950014 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950015 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950016 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950017 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950020 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950021 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950022 |
RESPONSE-950-DATA-LEAKAGES | — | — |
950100 |
RESPONSE-950-DATA-LEAKAGES | The Application Returned a 500-Level Status Code | — |
950130 |
RESPONSE-950-DATA-LEAKAGES | Directory Listing | — |
950140 |
RESPONSE-950-DATA-LEAKAGES | CGI source code leakage | — |
951011 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951012 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951013 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951014 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951015 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951016 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951017 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951018 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951100 |
RESPONSE-951-DATA-LEAKAGES-SQL | — | — |
951110 |
RESPONSE-951-DATA-LEAKAGES-SQL | Microsoft Access SQL Information Leakage | — |
951120 |
RESPONSE-951-DATA-LEAKAGES-SQL | Oracle SQL Information Leakage | — |
951130 |
RESPONSE-951-DATA-LEAKAGES-SQL | DB2 SQL Information Leakage | — |
951140 |
RESPONSE-951-DATA-LEAKAGES-SQL | EMC SQL Information Leakage | — |
951150 |
RESPONSE-951-DATA-LEAKAGES-SQL | firebird SQL Information Leakage | — |
951160 |
RESPONSE-951-DATA-LEAKAGES-SQL | Frontbase SQL Information Leakage | — |
951170 |
RESPONSE-951-DATA-LEAKAGES-SQL | hsqldb SQL Information Leakage | — |
951180 |
RESPONSE-951-DATA-LEAKAGES-SQL | informix SQL Information Leakage | — |
951190 |
RESPONSE-951-DATA-LEAKAGES-SQL | ingres SQL Information Leakage | — |
951200 |
RESPONSE-951-DATA-LEAKAGES-SQL | interbase SQL Information Leakage | — |
951210 |
RESPONSE-951-DATA-LEAKAGES-SQL | maxDB SQL Information Leakage | — |
951220 |
RESPONSE-951-DATA-LEAKAGES-SQL | mssql SQL Information Leakage | — |
951230 |
RESPONSE-951-DATA-LEAKAGES-SQL | mysql SQL Information Leakage | — |
951240 |
RESPONSE-951-DATA-LEAKAGES-SQL | postgres SQL Information Leakage | — |
951250 |
RESPONSE-951-DATA-LEAKAGES-SQL | sqlite SQL Information Leakage | — |
951260 |
RESPONSE-951-DATA-LEAKAGES-SQL | Sybase SQL Information Leakage | — |
952011 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952012 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952013 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952014 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952015 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952016 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952017 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952018 |
RESPONSE-952-DATA-LEAKAGES-JAVA | — | — |
952100 |
RESPONSE-952-DATA-LEAKAGES-JAVA | Java Source Code Leakage | — |
952110 |
RESPONSE-952-DATA-LEAKAGES-JAVA | Java Errors | — |
953011 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953012 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953013 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953014 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953015 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953016 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953017 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953018 |
RESPONSE-953-DATA-LEAKAGES-PHP | — | — |
953100 |
RESPONSE-953-DATA-LEAKAGES-PHP | PHP Information Leakage | — |
953110 |
RESPONSE-953-DATA-LEAKAGES-PHP | PHP source code leakage | — |
953120 |
RESPONSE-953-DATA-LEAKAGES-PHP | PHP source code leakage | — |
954011 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954012 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954013 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954014 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954015 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954016 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954017 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954018 |
RESPONSE-954-DATA-LEAKAGES-IIS | — | — |
954100 |
RESPONSE-954-DATA-LEAKAGES-IIS | Disclosure of IIS install location | — |
954110 |
RESPONSE-954-DATA-LEAKAGES-IIS | Application Availability Error | — |
954120 |
RESPONSE-954-DATA-LEAKAGES-IIS | IIS Information Leakage | — |
954130 |
RESPONSE-954-DATA-LEAKAGES-IIS | IIS Information Leakage | — |
959011 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959012 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959013 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959014 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959015 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959016 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959017 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959018 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959060 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959061 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959062 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959063 |
RESPONSE-959-BLOCKING-EVALUATION | — | — |
959100 |
RESPONSE-959-BLOCKING-EVALUATION | Outbound Anomaly Score Exceeded (Total Score: %{TX.OUTBOUND_ANOMALY_SCORE}) | — |
980011 |
RESPONSE-980-CORRELATION | — | — |
980012 |
RESPONSE-980-CORRELATION | — | — |
980013 |
RESPONSE-980-CORRELATION | — | — |
980014 |
RESPONSE-980-CORRELATION | — | — |
980015 |
RESPONSE-980-CORRELATION | — | — |
980016 |
RESPONSE-980-CORRELATION | — | — |
980017 |
RESPONSE-980-CORRELATION | — | — |
980018 |
RESPONSE-980-CORRELATION | — | — |
980100 |
RESPONSE-980-CORRELATION | Correlated Successful Attack Identified: (Total Score: %{tx.anomaly_score}) Inbound Attack (Inbound Anomaly Score: %{TX.INBOUND_ANOMALY_SCORE}) + Outbound Data Leakage (Outbound Anomaly Score: %{TX.OUTBOUND_ANOMALY_SCORE}) | — |
980110 |
RESPONSE-980-CORRELATION | Correlated Attack Attempt Identified: (Total Score: %{tx.anomaly_score}) Inbound Attack (Inbound Anomaly Score: %{TX.INBOUND_ANOMALY_SCORE}) + Outbound Application Error (Outbound Anomaly Score: %{TX.OUTBOUND_ANOMALY_SCORE}) | — |
980115 |
RESPONSE-980-CORRELATION | — | — |
980120 |
RESPONSE-980-CORRELATION | Inbound Anomaly Score (Total Inbound Score: %{TX.INBOUND_ANOMALY_SCORE} - SQLI=%{tx.sql_injection_score},XSS=%{tx.xss_score},RFI=%{tx.rfi_score},LFI=%{tx.lfi_score},RCE=%{tx.rce_score},PHPI=%{tx.php_injection_score},HTTP=%{tx.http_violation_score},SESS=%{tx.session_fixation_score}): individual paranoia level scores: %{TX.ANOMALY_SCORE_PL1}, %{TX.ANOMALY_SCORE_PL2}, %{TX.ANOMALY_SCORE_PL3}, %{TX.ANOMALY_SCORE_PL4} | — |
980130 |
RESPONSE-980-CORRELATION | Inbound Anomaly Score Exceeded (Total Inbound Score: %{TX.INBOUND_ANOMALY_SCORE} - SQLI=%{tx.sql_injection_score},XSS=%{tx.xss_score},RFI=%{tx.rfi_score},LFI=%{tx.lfi_score},RCE=%{tx.rce_score},PHPI=%{tx.php_injection_score},HTTP=%{tx.http_violation_score},SESS=%{tx.session_fixation_score}): individual paranoia level scores: %{TX.ANOMALY_SCORE_PL1}, %{TX.ANOMALY_SCORE_PL2}, %{TX.ANOMALY_SCORE_PL3}, %{TX.ANOMALY_SCORE_PL4} | — |
980140 |
RESPONSE-980-CORRELATION | Outbound Anomaly Score Exceeded (score %{TX.OUTBOUND_ANOMALY_SCORE}): individual paranoia level scores: %{TX.OUTBOUND_ANOMALY_SCORE_PL1}, %{TX.OUTBOUND_ANOMALY_SCORE_PL2}, %{TX.OUTBOUND_ANOMALY_SCORE_PL3}, %{TX.OUTBOUND_ANOMALY_SCORE_PL4} | — |
980145 |
RESPONSE-980-CORRELATION | — | — |
980150 |
RESPONSE-980-CORRELATION | Outbound Anomaly Score (Total Outbound Score: %{TX.OUTBOUND_ANOMALY_SCORE}): individual paranoia level scores: %{TX.OUTBOUND_ANOMALY_SCORE_PL1}, %{TX.OUTBOUND_ANOMALY_SCORE_PL2}, %{TX.OUTBOUND_ANOMALY_SCORE_PL3}, %{TX.OUTBOUND_ANOMALY_SCORE_PL4} | — |
9000001 |
Custom | — | — |
9000002 |
Custom | — | — |
9001000 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001001 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001100 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001110 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001112 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001114 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001116 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001122 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001124 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001126 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001128 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001140 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001160 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001170 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001180 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001182 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001184 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001200 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001202 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001204 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001206 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001208 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001210 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001212 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001214 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9001216 |
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES | — | — |
9002000 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002001 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002100 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002120 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002130 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002140 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002141 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002142 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002143 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002150 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002160 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002200 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002300 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002400 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002401 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002410 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002420 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002520 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002530 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002540 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002600 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002700 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002710 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002720 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002730 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002740 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002750 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002760 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002770 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002800 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002810 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002820 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002830 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9002900 |
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES | — | — |
9003000 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003001 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003100 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003105 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003110 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003115 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003116 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003120 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003121 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003125 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003130 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003140 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003150 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003155 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003160 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003300 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003310 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003320 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003321 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003330 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003331 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003340 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003350 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003400 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003410 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003500 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9003610 |
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES | — | — |
9004000 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004001 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004100 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004110 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004130 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004200 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004300 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004310 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004320 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004370 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9004380 |
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES | — | — |
9005000 |
REQUEST-903.9005-CPANEL-EXCLUSION-RULES | — | — |
9005001 |
REQUEST-903.9005-CPANEL-EXCLUSION-RULES | — | — |
9005100 |
REQUEST-903.9005-CPANEL-EXCLUSION-RULES | — | — |
9006000 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006001 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006100 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006110 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006120 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006130 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006140 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006150 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006155 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006160 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006170 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006200 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006210 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006220 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006230 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006240 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006300 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006310 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006315 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006320 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006330 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006340 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006400 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006410 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006420 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006500 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006510 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006600 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006700 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006710 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006800 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006900 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006901 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006910 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006920 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006930 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006940 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006950 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006960 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
9006970 |
REQUEST-903.9006-XENFORO-EXCLUSION-RULES | — | — |
| IP | Peristiwa |
|---|---|
198.51.100.33 | 5 |
198.51.100.21 | 5 |
198.51.100.27 | 4 |
198.51.100.23 | 4 |
198.51.100.32 | 3 |
198.51.100.22 | 3 |
198.51.100.34 | 2 |
198.51.100.15 | 2 |
198.51.100.12 | 2 |
198.51.100.11 | 2 |
| URI | Peristiwa |
|---|---|
/index.php?id=1 | 11 |
/.env | 6 |
/api/v1/login | 6 |
/xmlrpc.php | 6 |
/wp-login.php | 5 |
/?q=../../etc/passwd | 5 |
/admin/ | 4 |
| ID aturan | Pemicuan |
|---|---|
942100SQL Injection via libinjection |
11 |
930100Path Traversal (/../) |
11 |
913100Security scanner — User-Agent |
9 |
932100RCE — Unix commands |
9 |
941100XSS via libinjection |
3 |
| Waktu | IP | URI | Tipe | Aturan | Aksi |
|---|---|---|---|---|---|
| 2026-08-13 22:44:12 | 198.51.100.34 |
/.env |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 22:33:49 | 198.51.100.27 |
/.env |
RCE | 930100 Path Traversal (/../) |
Diblokir |
| 2026-08-13 21:49:22 | 198.51.100.33 |
/index.php?id=1 |
SQL Injection | 942100 SQL Injection via libinjection |
Diblokir |
| 2026-08-13 21:12:03 | 198.51.100.15 |
/wp-login.php |
SQL Injection | 913100 Security scanner — User-Agent |
Terdeteksi |
| 2026-08-13 22:13:56 | 198.51.100.32 |
/index.php?id=1 |
RCE | 930100 Path Traversal (/../) |
Diblokir |
| 2026-08-13 20:22:07 | 198.51.100.27 |
/api/v1/login |
SQL Injection | 932100 RCE — Unix commands |
Terdeteksi |
| 2026-08-13 20:44:24 | 198.51.100.33 |
/wp-login.php |
SQL Injection | 930100 Path Traversal (/../) |
Terdeteksi |
| 2026-08-13 20:37:58 | 198.51.100.35 |
/xmlrpc.php |
LFI/Path Traversal | 941100 XSS via libinjection |
Terdeteksi |
| 2026-08-13 19:57:08 | 198.51.100.22 |
/xmlrpc.php |
Protocol Attack | 932100 RCE — Unix commands |
Terdeteksi |
| 2026-08-13 18:37:54 | 198.51.100.22 |
/xmlrpc.php |
SQL Injection | 913100 Security scanner — User-Agent |
Diblokir |
| 2026-08-13 20:27:52 | 198.51.100.12 |
/admin/ |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Diblokir |
| 2026-08-13 20:57:30 | 198.51.100.11 |
/index.php?id=1 |
Scanner | 913100 Security scanner — User-Agent |
Terdeteksi |
| 2026-08-13 21:36:48 | 198.51.100.23 |
/api/v1/login |
SQL Injection | 930100 Path Traversal (/../) |
Terdeteksi |
| 2026-08-13 19:12:44 | 198.51.100.22 |
/api/v1/login |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Terdeteksi |
| 2026-08-13 16:24:20 | 198.51.100.21 |
/api/v1/login |
Protocol Attack | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 20:21:27 | 198.51.100.21 |
/.env |
LFI/Path Traversal | 932100 RCE — Unix commands |
Diblokir |
| 2026-08-13 14:57:00 | 198.51.100.33 |
/?q=../../etc/passwd |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 13:58:54 | 198.51.100.32 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Diblokir |
| 2026-08-13 21:31:00 | 198.51.100.21 |
/index.php?id=1 |
XSS | 913100 Security scanner — User-Agent |
Terdeteksi |
| 2026-08-13 14:40:20 | 198.51.100.24 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Terdeteksi |
| 2026-08-13 17:19:52 | 198.51.100.20 |
/.env |
XSS | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 21:31:24 | 198.51.100.33 |
/api/v1/login |
Protocol Attack | 942100 SQL Injection via libinjection |
Diblokir |
| 2026-08-13 19:29:52 | 198.51.100.23 |
/index.php?id=1 |
Protocol Attack | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 14:17:26 | 198.51.100.15 |
/index.php?id=1 |
LFI/Path Traversal | 932100 RCE — Unix commands |
Diblokir |
| 2026-08-13 18:49:48 | 198.51.100.25 |
/xmlrpc.php |
Scanner | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 11:13:47 | 198.51.100.23 |
/wp-login.php |
RCE | 913100 Security scanner — User-Agent |
Diblokir |
| 2026-08-13 09:03:54 | 198.51.100.27 |
/?q=../../etc/passwd |
XSS | 913100 Security scanner — User-Agent |
Terdeteksi |
| 2026-08-13 13:44:12 | 198.51.100.14 |
/index.php?id=1 |
Scanner | 930100 Path Traversal (/../) |
Diblokir |
| 2026-08-13 11:36:52 | 198.51.100.19 |
/?q=../../etc/passwd |
LFI/Path Traversal | 941100 XSS via libinjection |
Diblokir |
| 2026-08-13 14:43:17 | 198.51.100.34 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Terdeteksi |
| 2026-08-13 09:05:42 | 198.51.100.27 |
/index.php?id=1 |
RCE | 932100 RCE — Unix commands |
Terdeteksi |
| 2026-08-13 05:44:18 | 198.51.100.26 |
/xmlrpc.php |
XSS | 932100 RCE — Unix commands |
Diblokir |
| 2026-08-13 10:34:04 | 198.51.100.33 |
/admin/ |
RCE | 942100 SQL Injection via libinjection |
Diblokir |
| 2026-08-13 06:47:45 | 198.51.100.11 |
/index.php?id=1 |
SQL Injection | 941100 XSS via libinjection |
Terdeteksi |
| 2026-08-13 05:46:28 | 198.51.100.24 |
/.env |
SQL Injection | 932100 RCE — Unix commands |
Terdeteksi |
| 2026-08-13 04:31:37 | 198.51.100.23 |
/.env |
SQL Injection | 913100 Security scanner — User-Agent |
Terdeteksi |
| 2026-08-13 20:04:36 | 198.51.100.28 |
/admin/ |
SQL Injection | 942100 SQL Injection via libinjection |
Terdeteksi |
| 2026-08-13 04:42:34 | 198.51.100.12 |
/wp-login.php |
LFI/Path Traversal | 932100 RCE — Unix commands |
Diblokir |
| 2026-08-13 04:50:04 | 198.51.100.21 |
/wp-login.php |
SQL Injection | 942100 SQL Injection via libinjection |
Diblokir |
| 2026-08-13 10:06:57 | 198.51.100.32 |
/index.php?id=1 |
Protocol Attack | 930100 Path Traversal (/../) |
Diblokir |
| 2026-08-13 16:44:52 | 198.51.100.19 |
/?q=../../etc/passwd |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Diblokir |
| 2026-08-13 16:08:33 | 198.51.100.21 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
Diblokir |
| 2026-08-13 02:50:00 | 198.51.100.14 |
/admin/ |
RCE | 930100 Path Traversal (/../) |
Terdeteksi |