ModSecurity

ModSecurity WAF
Cache: 23:54:38 Vernieuwen
ModSecurity Actief
Vandaag
2788
Geblokkeerd
160
Totaal in steekproef
2788
Unieke IP's
10
Regellijst niet beschikbaar — werk de monitor-modsec-wrapper bij met een ---RULES---sectie (zie FAQ).
Aanvalstypen
RCE
19
Protocol Attack
15
SQL Injection
14
LFI/Path Traversal
13
Scanner
13
XSS
12
Top aanvallende IP's
IPGebeurtenissen
198.51.100.189
198.51.100.227
198.51.100.356
198.51.100.215
198.51.100.135
198.51.100.244
198.51.100.274
198.51.100.154
198.51.100.194
198.51.100.143
Top doel-URL's
URIGebeurtenissen
/.env17
/api/v1/login14
/index.php?id=113
/?q=../../etc/passwd11
/admin/11
/wp-login.php11
/xmlrpc.php9
Top geactiveerde regels
Regel-IDActiveringen
930100
Path Traversal (/../)
22
932100
RCE — Unix commands
20
941100
XSS via libinjection
18
942100
SQL Injection via libinjection
14
913100
Security scanner — User-Agent
12
Recente gebeurtenissen 86 records
TijdIPURITypeRegelActie
2026-10-11 23:54:38 198.51.100.26 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 23:46:26 198.51.100.21 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Geblokkeerd
2026-10-11 23:39:26 198.51.100.24 /.env XSS 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 22:21:17 198.51.100.18 /?q=../../etc/passwd XSS 913100
Security scanner — User-Agent
Geblokkeerd
2026-10-11 23:30:14 198.51.100.14 /.env XSS 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 21:28:48 198.51.100.28 /admin/ Scanner 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 20:46:50 198.51.100.18 /wp-login.php LFI/Path Traversal 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 22:08:14 198.51.100.27 /index.php?id=1 LFI/Path Traversal 941100
XSS via libinjection
Gedetecteerd
2026-10-11 20:28:30 198.51.100.22 /xmlrpc.php SQL Injection 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 20:20:26 198.51.100.12 /api/v1/login RCE 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 19:52:48 198.51.100.16 /.env LFI/Path Traversal 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 21:17:53 198.51.100.11 /admin/ LFI/Path Traversal 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 18:49:14 198.51.100.17 /index.php?id=1 Protocol Attack 941100
XSS via libinjection
Geblokkeerd
2026-10-11 20:45:42 198.51.100.15 /api/v1/login SQL Injection 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 17:43:52 198.51.100.18 /api/v1/login Scanner 941100
XSS via libinjection
Gedetecteerd
2026-10-11 19:30:08 198.51.100.16 /index.php?id=1 Scanner 941100
XSS via libinjection
Gedetecteerd
2026-10-11 17:48:14 198.51.100.22 /.env XSS 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 22:00:10 198.51.100.26 /wp-login.php SQL Injection 941100
XSS via libinjection
Gedetecteerd
2026-10-11 18:40:14 198.51.100.15 /xmlrpc.php Scanner 913100
Security scanner — User-Agent
Geblokkeerd
2026-10-11 17:04:52 198.51.100.30 /wp-login.php RCE 941100
XSS via libinjection
Gedetecteerd
2026-10-11 18:53:38 198.51.100.35 /index.php?id=1 XSS 941100
XSS via libinjection
Geblokkeerd
2026-10-11 14:13:38 198.51.100.33 /admin/ Protocol Attack 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 16:13:00 198.51.100.22 /api/v1/login Protocol Attack 941100
XSS via libinjection
Gedetecteerd
2026-10-11 16:52:12 198.51.100.33 /api/v1/login Protocol Attack 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 18:50:14 198.51.100.18 /wp-login.php RCE 913100
Security scanner — User-Agent
Geblokkeerd
2026-10-11 11:21:18 198.51.100.33 /?q=../../etc/passwd Protocol Attack 941100
XSS via libinjection
Gedetecteerd
2026-10-11 18:56:04 198.51.100.22 /admin/ XSS 942100
SQL Injection via libinjection
Geblokkeerd
2026-10-11 15:49:32 198.51.100.23 /admin/ Scanner 932100
RCE — Unix commands
Geblokkeerd
2026-10-11 11:40:06 198.51.100.19 /admin/ RCE 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 08:49:50 198.51.100.18 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 17:49:38 198.51.100.22 /admin/ SQL Injection 941100
XSS via libinjection
Gedetecteerd
2026-10-11 14:31:59 198.51.100.34 /.env LFI/Path Traversal 932100
RCE — Unix commands
Geblokkeerd
2026-10-11 20:06:54 198.51.100.19 /.env RCE 941100
XSS via libinjection
Gedetecteerd
2026-10-11 06:15:20 198.51.100.35 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 05:41:32 198.51.100.15 /index.php?id=1 SQL Injection 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-11 13:13:33 198.51.100.21 /index.php?id=1 XSS 941100
XSS via libinjection
Gedetecteerd
2026-10-11 18:39:02 198.51.100.35 /.env XSS 941100
XSS via libinjection
Gedetecteerd
2026-10-11 15:35:45 198.51.100.32 /xmlrpc.php LFI/Path Traversal 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 04:29:18 198.51.100.17 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-11 04:31:08 198.51.100.22 /.env Scanner 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 06:53:18 198.51.100.24 /api/v1/login RCE 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 13:49:12 198.51.100.25 /xmlrpc.php RCE 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 12:51:44 198.51.100.19 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 01:02:56 198.51.100.17 /.env LFI/Path Traversal 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-11 15:31:34 198.51.100.21 /.env RCE 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 07:19:23 198.51.100.18 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Geblokkeerd
2026-10-11 17:20:34 198.51.100.18 /api/v1/login XSS 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 05:16:49 198.51.100.19 /xmlrpc.php Scanner 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 11:49:50 198.51.100.27 /wp-login.php SQL Injection 932100
RCE — Unix commands
Geblokkeerd
2026-10-11 11:11:03 198.51.100.18 /.env Scanner 913100
Security scanner — User-Agent
Geblokkeerd
2026-10-11 17:01:18 198.51.100.24 /.env SQL Injection 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-11 02:58:20 198.51.100.12 /?q=../../etc/passwd RCE 941100
XSS via libinjection
Gedetecteerd
2026-10-11 04:50:38 198.51.100.27 /admin/ RCE 930100
Path Traversal (/../)
Gedetecteerd
2026-10-10 20:18:23 198.51.100.35 /xmlrpc.php RCE 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 13:11:08 198.51.100.14 /api/v1/login Scanner 930100
Path Traversal (/../)
Gedetecteerd
2026-10-10 21:27:53 198.51.100.18 /.env Scanner 941100
XSS via libinjection
Gedetecteerd
2026-10-11 05:24:54 198.51.100.20 /api/v1/login RCE 941100
XSS via libinjection
Geblokkeerd
2026-10-11 04:43:14 198.51.100.13 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 13:27:16 198.51.100.23 /wp-login.php RCE 941100
XSS via libinjection
Gedetecteerd
2026-10-11 05:13:38 198.51.100.11 /wp-login.php XSS 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 18:40:38 198.51.100.31 /?q=../../etc/passwd SQL Injection 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-10 15:00:16 198.51.100.21 /api/v1/login Scanner 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 02:27:06 198.51.100.29 /xmlrpc.php LFI/Path Traversal 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-10 15:27:56 198.51.100.14 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Gedetecteerd
2026-10-10 14:33:34 198.51.100.35 /?q=../../etc/passwd Scanner 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 11:39:03 198.51.100.22 /?q=../../etc/passwd SQL Injection 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 17:35:08 198.51.100.24 /wp-login.php RCE 941100
XSS via libinjection
Gedetecteerd
2026-10-11 17:30:30 198.51.100.13 /index.php?id=1 LFI/Path Traversal 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 12:09:42 198.51.100.21 /index.php?id=1 RCE 930100
Path Traversal (/../)
Gedetecteerd
2026-10-10 13:52:14 198.51.100.32 /api/v1/login Scanner 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 13:35:08 198.51.100.35 /.env Protocol Attack 913100
Security scanner — User-Agent
Gedetecteerd
2026-10-11 16:37:59 198.51.100.15 /index.php?id=1 XSS 930100
Path Traversal (/../)
Geblokkeerd
2026-10-11 11:39:02 198.51.100.25 /?q=../../etc/passwd Protocol Attack 932100
RCE — Unix commands
Gedetecteerd
2026-10-11 18:54:07 198.51.100.13 /.env Protocol Attack 932100
RCE — Unix commands
Geblokkeerd
2026-10-10 10:39:50 198.51.100.11 /api/v1/login LFI/Path Traversal 932100
RCE — Unix commands
Geblokkeerd
2026-10-11 09:52:08 198.51.100.16 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Geblokkeerd
2026-10-10 19:15:46 198.51.100.34 /admin/ SQL Injection 932100
RCE — Unix commands
Gedetecteerd
2026-10-10 20:40:57 198.51.100.28 /.env RCE 932100
RCE — Unix commands
Geblokkeerd
2026-10-11 04:09:02 198.51.100.13 /admin/ Protocol Attack 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 15:55:22 198.51.100.25 /admin/ SQL Injection 932100
RCE — Unix commands
Gedetecteerd
2026-10-10 15:17:18 198.51.100.28 /api/v1/login RCE 942100
SQL Injection via libinjection
Geblokkeerd
2026-10-10 10:33:38 198.51.100.30 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Gedetecteerd
2026-10-10 16:43:40 198.51.100.27 /.env SQL Injection 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 05:59:47 198.51.100.20 /index.php?id=1 LFI/Path Traversal 942100
SQL Injection via libinjection
Gedetecteerd
2026-10-11 10:36:38 198.51.100.13 /index.php?id=1 Protocol Attack 930100
Path Traversal (/../)
Gedetecteerd
2026-10-11 11:12:28 198.51.100.31 /api/v1/login XSS 930100
Path Traversal (/../)
Geblokkeerd

Een ModSecurity log viewer voor het auditlog

ModSecurity met de OWASP Core Rule Set blokkeert bijzonder veel, en schrijft over vrijwel alles daarvan naar een auditlog waarvan het formaat voor machines is bedacht. Deze pagina maakt daar iets leesbaars van: welke verzoeken werden geblokkeerd, welke regel afging, wat de anomaliescore was en waar het verzoek vandaan kwam.

De reden om hier regelmatig te kijken zijn de valse positieven. De Core Rule Set is bewust streng en blokkeert op het standaard paranoia-niveau legitiem verkeer in de meeste echte toepassingen: bestandsuploads, rich-text-editors en alles wat opmaak of SQL-achtige tekenreeksen verstuurt zijn de gebruikelijke slachtoffers. Het patroon om te herkennen is dezelfde regel-ID die keer op keer afgaat op hetzelfde eindpunt vanaf veel verschillende adressen. Dat is geen aanval, dat is uw eigen toepassing die gepakt wordt.

Houd de uitzondering dan smal: sluit die ene regel uit voor die ene parameter op dat ene pad, niet de hele regel en zeker niet de hele categorie. De pagina toont ook de actieve regelset, zodat u na een wijziging kunt nagaan wat er werkelijk geladen is.