| IP | Hendelser |
|---|---|
198.51.100.18 | 9 |
198.51.100.22 | 7 |
198.51.100.35 | 6 |
198.51.100.21 | 5 |
198.51.100.13 | 5 |
198.51.100.24 | 4 |
198.51.100.27 | 4 |
198.51.100.15 | 4 |
198.51.100.19 | 4 |
198.51.100.14 | 3 |
| URI | Hendelser |
|---|---|
/.env | 17 |
/api/v1/login | 14 |
/index.php?id=1 | 13 |
/?q=../../etc/passwd | 11 |
/admin/ | 11 |
/wp-login.php | 11 |
/xmlrpc.php | 9 |
| Regel-ID | Treff |
|---|---|
930100Path Traversal (/../) |
22 |
932100RCE — Unix commands |
20 |
941100XSS via libinjection |
18 |
942100SQL Injection via libinjection |
14 |
913100Security scanner — User-Agent |
12 |
| Tid | IP | URI | Type | Regel | Handling |
|---|---|---|---|---|---|
| 2026-10-11 23:54:38 | 198.51.100.26 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 23:46:26 | 198.51.100.21 |
/xmlrpc.php |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Blokkert |
| 2026-10-11 23:39:26 | 198.51.100.24 |
/.env |
XSS | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 22:21:17 | 198.51.100.18 |
/?q=../../etc/passwd |
XSS | 913100 Security scanner — User-Agent |
Blokkert |
| 2026-10-11 23:30:14 | 198.51.100.14 |
/.env |
XSS | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 21:28:48 | 198.51.100.28 |
/admin/ |
Scanner | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 20:46:50 | 198.51.100.18 |
/wp-login.php |
LFI/Path Traversal | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 22:08:14 | 198.51.100.27 |
/index.php?id=1 |
LFI/Path Traversal | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 20:28:30 | 198.51.100.22 |
/xmlrpc.php |
SQL Injection | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 20:20:26 | 198.51.100.12 |
/api/v1/login |
RCE | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 19:52:48 | 198.51.100.16 |
/.env |
LFI/Path Traversal | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 21:17:53 | 198.51.100.11 |
/admin/ |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 18:49:14 | 198.51.100.17 |
/index.php?id=1 |
Protocol Attack | 941100 XSS via libinjection |
Blokkert |
| 2026-10-11 20:45:42 | 198.51.100.15 |
/api/v1/login |
SQL Injection | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 17:43:52 | 198.51.100.18 |
/api/v1/login |
Scanner | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 19:30:08 | 198.51.100.16 |
/index.php?id=1 |
Scanner | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 17:48:14 | 198.51.100.22 |
/.env |
XSS | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 22:00:10 | 198.51.100.26 |
/wp-login.php |
SQL Injection | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 18:40:14 | 198.51.100.15 |
/xmlrpc.php |
Scanner | 913100 Security scanner — User-Agent |
Blokkert |
| 2026-10-11 17:04:52 | 198.51.100.30 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 18:53:38 | 198.51.100.35 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Blokkert |
| 2026-10-11 14:13:38 | 198.51.100.33 |
/admin/ |
Protocol Attack | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 16:13:00 | 198.51.100.22 |
/api/v1/login |
Protocol Attack | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 16:52:12 | 198.51.100.33 |
/api/v1/login |
Protocol Attack | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 18:50:14 | 198.51.100.18 |
/wp-login.php |
RCE | 913100 Security scanner — User-Agent |
Blokkert |
| 2026-10-11 11:21:18 | 198.51.100.33 |
/?q=../../etc/passwd |
Protocol Attack | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 18:56:04 | 198.51.100.22 |
/admin/ |
XSS | 942100 SQL Injection via libinjection |
Blokkert |
| 2026-10-11 15:49:32 | 198.51.100.23 |
/admin/ |
Scanner | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-11 11:40:06 | 198.51.100.19 |
/admin/ |
RCE | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 08:49:50 | 198.51.100.18 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 17:49:38 | 198.51.100.22 |
/admin/ |
SQL Injection | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 14:31:59 | 198.51.100.34 |
/.env |
LFI/Path Traversal | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-11 20:06:54 | 198.51.100.19 |
/.env |
RCE | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 06:15:20 | 198.51.100.35 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 05:41:32 | 198.51.100.15 |
/index.php?id=1 |
SQL Injection | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-11 13:13:33 | 198.51.100.21 |
/index.php?id=1 |
XSS | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 18:39:02 | 198.51.100.35 |
/.env |
XSS | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 15:35:45 | 198.51.100.32 |
/xmlrpc.php |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 04:29:18 | 198.51.100.17 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-11 04:31:08 | 198.51.100.22 |
/.env |
Scanner | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 06:53:18 | 198.51.100.24 |
/api/v1/login |
RCE | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 13:49:12 | 198.51.100.25 |
/xmlrpc.php |
RCE | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 12:51:44 | 198.51.100.19 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 01:02:56 | 198.51.100.17 |
/.env |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-11 15:31:34 | 198.51.100.21 |
/.env |
RCE | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 07:19:23 | 198.51.100.18 |
/xmlrpc.php |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Blokkert |
| 2026-10-11 17:20:34 | 198.51.100.18 |
/api/v1/login |
XSS | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 05:16:49 | 198.51.100.19 |
/xmlrpc.php |
Scanner | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 11:49:50 | 198.51.100.27 |
/wp-login.php |
SQL Injection | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-11 11:11:03 | 198.51.100.18 |
/.env |
Scanner | 913100 Security scanner — User-Agent |
Blokkert |
| 2026-10-11 17:01:18 | 198.51.100.24 |
/.env |
SQL Injection | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-11 02:58:20 | 198.51.100.12 |
/?q=../../etc/passwd |
RCE | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 04:50:38 | 198.51.100.27 |
/admin/ |
RCE | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-10 20:18:23 | 198.51.100.35 |
/xmlrpc.php |
RCE | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 13:11:08 | 198.51.100.14 |
/api/v1/login |
Scanner | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-10 21:27:53 | 198.51.100.18 |
/.env |
Scanner | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 05:24:54 | 198.51.100.20 |
/api/v1/login |
RCE | 941100 XSS via libinjection |
Blokkert |
| 2026-10-11 04:43:14 | 198.51.100.13 |
/index.php?id=1 |
SQL Injection | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 13:27:16 | 198.51.100.23 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 05:13:38 | 198.51.100.11 |
/wp-login.php |
XSS | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 18:40:38 | 198.51.100.31 |
/?q=../../etc/passwd |
SQL Injection | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-10 15:00:16 | 198.51.100.21 |
/api/v1/login |
Scanner | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 02:27:06 | 198.51.100.29 |
/xmlrpc.php |
LFI/Path Traversal | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-10 15:27:56 | 198.51.100.14 |
/wp-login.php |
Protocol Attack | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-10 14:33:34 | 198.51.100.35 |
/?q=../../etc/passwd |
Scanner | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 11:39:03 | 198.51.100.22 |
/?q=../../etc/passwd |
SQL Injection | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 17:35:08 | 198.51.100.24 |
/wp-login.php |
RCE | 941100 XSS via libinjection |
Oppdaget |
| 2026-10-11 17:30:30 | 198.51.100.13 |
/index.php?id=1 |
LFI/Path Traversal | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 12:09:42 | 198.51.100.21 |
/index.php?id=1 |
RCE | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-10 13:52:14 | 198.51.100.32 |
/api/v1/login |
Scanner | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 13:35:08 | 198.51.100.35 |
/.env |
Protocol Attack | 913100 Security scanner — User-Agent |
Oppdaget |
| 2026-10-11 16:37:59 | 198.51.100.15 |
/index.php?id=1 |
XSS | 930100 Path Traversal (/../) |
Blokkert |
| 2026-10-11 11:39:02 | 198.51.100.25 |
/?q=../../etc/passwd |
Protocol Attack | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-11 18:54:07 | 198.51.100.13 |
/.env |
Protocol Attack | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-10 10:39:50 | 198.51.100.11 |
/api/v1/login |
LFI/Path Traversal | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-11 09:52:08 | 198.51.100.16 |
/?q=../../etc/passwd |
RCE | 913100 Security scanner — User-Agent |
Blokkert |
| 2026-10-10 19:15:46 | 198.51.100.34 |
/admin/ |
SQL Injection | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-10 20:40:57 | 198.51.100.28 |
/.env |
RCE | 932100 RCE — Unix commands |
Blokkert |
| 2026-10-11 04:09:02 | 198.51.100.13 |
/admin/ |
Protocol Attack | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 15:55:22 | 198.51.100.25 |
/admin/ |
SQL Injection | 932100 RCE — Unix commands |
Oppdaget |
| 2026-10-10 15:17:18 | 198.51.100.28 |
/api/v1/login |
RCE | 942100 SQL Injection via libinjection |
Blokkert |
| 2026-10-10 10:33:38 | 198.51.100.30 |
/?q=../../etc/passwd |
Protocol Attack | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-10 16:43:40 | 198.51.100.27 |
/.env |
SQL Injection | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 05:59:47 | 198.51.100.20 |
/index.php?id=1 |
LFI/Path Traversal | 942100 SQL Injection via libinjection |
Oppdaget |
| 2026-10-11 10:36:38 | 198.51.100.13 |
/index.php?id=1 |
Protocol Attack | 930100 Path Traversal (/../) |
Oppdaget |
| 2026-10-11 11:12:28 | 198.51.100.31 |
/api/v1/login |
XSS | 930100 Path Traversal (/../) |
Blokkert |
ModSecurity med OWASP Core Rule Set blokkerer svært mye, og skriver om nesten alt av det til en revisjonslogg hvis format er laget for maskiner. Denne siden gjør det om til noe lesbart: hvilke forespørsler som ble blokkert, hvilken regel som slo til, hva anomalipoengsummen var og hvor forespørselen kom fra.
Grunnen til å se hit jevnlig er falske positiver. Core Rule Set er bevisst strengt og blokkerer på standardnivået legitim trafikk i de fleste virkelige applikasjoner: filopplastinger, redigeringsverktøy med formatert tekst og alt som sender markup eller SQL-liknende strenger er de vanlige ofrene. Mønsteret å kjenne igjen er samme regel-ID som slår til gang på gang mot samme endepunkt fra mange forskjellige adresser. Det er ikke et angrep, det er din egen applikasjon som blir tatt.
Hold unntaket smalt når du finner et: utelat akkurat den regelen for akkurat den parameteren på akkurat den stien, aldri hele regelen og enda mindre hele kategorien. Siden lister også det aktive regelsettet, slik at du etter en endring kan bekrefte hva som faktisk er lastet inn.