| IP | Gebeurtenissen |
|---|---|
198.51.100.18 | 9 |
198.51.100.22 | 7 |
198.51.100.35 | 6 |
198.51.100.21 | 5 |
198.51.100.13 | 5 |
198.51.100.24 | 4 |
198.51.100.27 | 4 |
198.51.100.15 | 4 |
198.51.100.19 | 4 |
198.51.100.14 | 3 |
| URI | Gebeurtenissen |
|---|---|
/.env | 17 |
/api/v1/login | 14 |
/index.php?id=1 | 13 |
/?q=../../etc/passwd | 11 |
/admin/ | 11 |
/wp-login.php | 11 |
/xmlrpc.php | 9 |
| Regel-ID | Activeringen |
|---|---|
930100Path Traversal (/../) |
22 |
932100RCE — Unix commands |
20 |
941100XSS via libinjection |
18 |
942100SQL Injection via libinjection |
14 |
913100Security scanner — User-Agent |
12 |
| Tijd | IP | URI | Type | Regel | Actie |
|---|---|---|---|---|---|
| 2026-10-11 23:54:38 | 198.51.100.26 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 23:46:26 | 198.51.100.21 |
/xmlrpc.php |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Geblokkeerd |
| 2026-10-11 23:39:26 | 198.51.100.24 |
/.env |
XSS | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 22:21:17 | 198.51.100.18 |
/?q=../../etc/passwd |
XSS | 913100 Security scanner — User-Agent |
Geblokkeerd |
| 2026-10-11 23:30:14 | 198.51.100.14 |
/.env |
XSS | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 21:28:48 | 198.51.100.28 |
/admin/ |
Scanner | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 20:46:50 | 198.51.100.18 |
/wp-login.php |
LFI/Path Traversal | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 22:08:14 | 198.51.100.27 |
/index.php?id=1 |
LFI/Path Traversal | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 20:28:30 | 198.51.100.22 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 20:20:26 | 198.51.100.12 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 19:52:48 | 198.51.100.16 |
/.env |
LFI/Path Traversal | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 21:17:53 | 198.51.100.11 |
/admin/ |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 18:49:14 | 198.51.100.17 |
/index.php?id=1 |
Protocol Attack | 941100 XSS via libinjection |
Geblokkeerd |
| 2026-10-11 20:45:42 | 198.51.100.15 |
/api/v1/login |
SQL Injection | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 17:43:52 | 198.51.100.18 |
/api/v1/login |
Scanner | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 19:30:08 | 198.51.100.16 |
/index.php?id=1 |
Scanner | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 17:48:14 | 198.51.100.22 |
/.env |
XSS | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 22:00:10 | 198.51.100.26 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 18:40:14 | 198.51.100.15 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
Geblokkeerd |
| 2026-10-11 17:04:52 | 198.51.100.30 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 18:53:38 | 198.51.100.35 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Geblokkeerd |
| 2026-10-11 14:13:38 | 198.51.100.33 |
/admin/ |
Protocol Attack | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 16:13:00 | 198.51.100.22 |
/api/v1/login |
Protocol Attack | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 16:52:12 | 198.51.100.33 |
/api/v1/login |
Protocol Attack | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 18:50:14 | 198.51.100.18 |
/wp-login.php |
RCE | 913100 Security scanner — User-Agent |
Geblokkeerd |
| 2026-10-11 11:21:18 | 198.51.100.33 |
/?q=../../etc/passwd |
Protocol Attack | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 18:56:04 | 198.51.100.22 |
/admin/ |
XSS | 942100 SQL Injection via libinjection |
Geblokkeerd |
| 2026-10-11 15:49:32 | 198.51.100.23 |
/admin/ |
Scanner | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-11 11:40:06 | 198.51.100.19 |
/admin/ |
RCE | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 08:49:50 | 198.51.100.18 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 17:49:38 | 198.51.100.22 |
/admin/ |
SQL Injection | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 14:31:59 | 198.51.100.34 |
/.env |
LFI/Path Traversal | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-11 20:06:54 | 198.51.100.19 |
/.env |
RCE | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 06:15:20 | 198.51.100.35 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 05:41:32 | 198.51.100.15 |
/index.php?id=1 |
SQL Injection | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-11 13:13:33 | 198.51.100.21 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 18:39:02 | 198.51.100.35 |
/.env |
XSS | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 15:35:45 | 198.51.100.32 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 04:29:18 | 198.51.100.17 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-11 04:31:08 | 198.51.100.22 |
/.env |
Scanner | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 06:53:18 | 198.51.100.24 |
/api/v1/login |
RCE | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 13:49:12 | 198.51.100.25 |
/xmlrpc.php |
RCE | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 12:51:44 | 198.51.100.19 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 01:02:56 | 198.51.100.17 |
/.env |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-11 15:31:34 | 198.51.100.21 |
/.env |
RCE | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 07:19:23 | 198.51.100.18 |
/xmlrpc.php |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Geblokkeerd |
| 2026-10-11 17:20:34 | 198.51.100.18 |
/api/v1/login |
XSS | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 05:16:49 | 198.51.100.19 |
/xmlrpc.php |
Scanner | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 11:49:50 | 198.51.100.27 |
/wp-login.php |
SQL Injection | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-11 11:11:03 | 198.51.100.18 |
/.env |
Scanner | 913100 Security scanner — User-Agent |
Geblokkeerd |
| 2026-10-11 17:01:18 | 198.51.100.24 |
/.env |
SQL Injection | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-11 02:58:20 | 198.51.100.12 |
/?q=../../etc/passwd |
RCE | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 04:50:38 | 198.51.100.27 |
/admin/ |
RCE | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-10 20:18:23 | 198.51.100.35 |
/xmlrpc.php |
RCE | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 13:11:08 | 198.51.100.14 |
/api/v1/login |
Scanner | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-10 21:27:53 | 198.51.100.18 |
/.env |
Scanner | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 05:24:54 | 198.51.100.20 |
/api/v1/login |
RCE | 941100 XSS via libinjection |
Geblokkeerd |
| 2026-10-11 04:43:14 | 198.51.100.13 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 13:27:16 | 198.51.100.23 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 05:13:38 | 198.51.100.11 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 18:40:38 | 198.51.100.31 |
/?q=../../etc/passwd |
SQL Injection | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-10 15:00:16 | 198.51.100.21 |
/api/v1/login |
Scanner | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 02:27:06 | 198.51.100.29 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-10 15:27:56 | 198.51.100.14 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-10 14:33:34 | 198.51.100.35 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 11:39:03 | 198.51.100.22 |
/?q=../../etc/passwd |
SQL Injection | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 17:35:08 | 198.51.100.24 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Gedetecteerd |
| 2026-10-11 17:30:30 | 198.51.100.13 |
/index.php?id=1 |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 12:09:42 | 198.51.100.21 |
/index.php?id=1 |
RCE | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-10 13:52:14 | 198.51.100.32 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 13:35:08 | 198.51.100.35 |
/.env |
Protocol Attack | 913100 Security scanner — User-Agent |
Gedetecteerd |
| 2026-10-11 16:37:59 | 198.51.100.15 |
/index.php?id=1 |
XSS | 930100 Path Traversal (/../) |
Geblokkeerd |
| 2026-10-11 11:39:02 | 198.51.100.25 |
/?q=../../etc/passwd |
Protocol Attack | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-11 18:54:07 | 198.51.100.13 |
/.env |
Protocol Attack | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-10 10:39:50 | 198.51.100.11 |
/api/v1/login |
LFI/Path Traversal | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-11 09:52:08 | 198.51.100.16 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Geblokkeerd |
| 2026-10-10 19:15:46 | 198.51.100.34 |
/admin/ |
SQL Injection | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-10 20:40:57 | 198.51.100.28 |
/.env |
RCE | 932100 RCE — Unix commands |
Geblokkeerd |
| 2026-10-11 04:09:02 | 198.51.100.13 |
/admin/ |
Protocol Attack | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 15:55:22 | 198.51.100.25 |
/admin/ |
SQL Injection | 932100 RCE — Unix commands |
Gedetecteerd |
| 2026-10-10 15:17:18 | 198.51.100.28 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
Geblokkeerd |
| 2026-10-10 10:33:38 | 198.51.100.30 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-10 16:43:40 | 198.51.100.27 |
/.env |
SQL Injection | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 05:59:47 | 198.51.100.20 |
/index.php?id=1 |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Gedetecteerd |
| 2026-10-11 10:36:38 | 198.51.100.13 |
/index.php?id=1 |
Protocol Attack | 930100 Path Traversal (/../) |
Gedetecteerd |
| 2026-10-11 11:12:28 | 198.51.100.31 |
/api/v1/login |
XSS | 930100 Path Traversal (/../) |
Geblokkeerd |
ModSecurity met de OWASP Core Rule Set blokkeert bijzonder veel, en schrijft over vrijwel alles daarvan naar een auditlog waarvan het formaat voor machines is bedacht. Deze pagina maakt daar iets leesbaars van: welke verzoeken werden geblokkeerd, welke regel afging, wat de anomaliescore was en waar het verzoek vandaan kwam.
De reden om hier regelmatig te kijken zijn de valse positieven. De Core Rule Set is bewust streng en blokkeert op het standaard paranoia-niveau legitiem verkeer in de meeste echte toepassingen: bestandsuploads, rich-text-editors en alles wat opmaak of SQL-achtige tekenreeksen verstuurt zijn de gebruikelijke slachtoffers. Het patroon om te herkennen is dezelfde regel-ID die keer op keer afgaat op hetzelfde eindpunt vanaf veel verschillende adressen. Dat is geen aanval, dat is uw eigen toepassing die gepakt wordt.
Houd de uitzondering dan smal: sluit die ene regel uit voor die ene parameter op dat ene pad, niet de hele regel en zeker niet de hele categorie. De pagina toont ook de actieve regelset, zodat u na een wijziging kunt nagaan wat er werkelijk geladen is.