ModSecurity

ModSecurity WAF
Cache: 23:54:38 Actualizează
ModSecurity Activ
Astăzi
2788
Blocat
160
Total în eșantion
2788
IP unice
10
Lista de reguli este indisponibilă — actualizați wrapper-ul monitor-modsec, adăugând secțiunea ---RULES--- (vezi FAQ).
Tipuri de atacuri
RCE
19
Protocol Attack
15
SQL Injection
14
LFI/Path Traversal
13
Scanner
13
XSS
12
Top IP atacatoare
IPEvenimente
198.51.100.189
198.51.100.227
198.51.100.356
198.51.100.215
198.51.100.135
198.51.100.244
198.51.100.274
198.51.100.154
198.51.100.194
198.51.100.143
Top URL-uri țintă
URIEvenimente
/.env17
/api/v1/login14
/index.php?id=113
/?q=../../etc/passwd11
/admin/11
/wp-login.php11
/xmlrpc.php9
Top reguli declanșate
ID regulăDeclanșări
930100
Path Traversal (/../)
22
932100
RCE — Unix commands
20
941100
XSS via libinjection
18
942100
SQL Injection via libinjection
14
913100
Security scanner — User-Agent
12
Evenimente recente 86 înregistrări
TimpIPURITipRegulăAcțiune
2026-10-11 23:54:38 198.51.100.26 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Detectat
2026-10-11 23:46:26 198.51.100.21 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Blocat
2026-10-11 23:39:26 198.51.100.24 /.env XSS 932100
RCE — Unix commands
Detectat
2026-10-11 22:21:17 198.51.100.18 /?q=../../etc/passwd XSS 913100
Security scanner — User-Agent
Blocat
2026-10-11 23:30:14 198.51.100.14 /.env XSS 942100
SQL Injection via libinjection
Detectat
2026-10-11 21:28:48 198.51.100.28 /admin/ Scanner 942100
SQL Injection via libinjection
Detectat
2026-10-11 20:46:50 198.51.100.18 /wp-login.php LFI/Path Traversal 932100
RCE — Unix commands
Detectat
2026-10-11 22:08:14 198.51.100.27 /index.php?id=1 LFI/Path Traversal 941100
XSS via libinjection
Detectat
2026-10-11 20:28:30 198.51.100.22 /xmlrpc.php SQL Injection 932100
RCE — Unix commands
Detectat
2026-10-11 20:20:26 198.51.100.12 /api/v1/login RCE 932100
RCE — Unix commands
Detectat
2026-10-11 19:52:48 198.51.100.16 /.env LFI/Path Traversal 932100
RCE — Unix commands
Detectat
2026-10-11 21:17:53 198.51.100.11 /admin/ LFI/Path Traversal 942100
SQL Injection via libinjection
Detectat
2026-10-11 18:49:14 198.51.100.17 /index.php?id=1 Protocol Attack 941100
XSS via libinjection
Blocat
2026-10-11 20:45:42 198.51.100.15 /api/v1/login SQL Injection 930100
Path Traversal (/../)
Blocat
2026-10-11 17:43:52 198.51.100.18 /api/v1/login Scanner 941100
XSS via libinjection
Detectat
2026-10-11 19:30:08 198.51.100.16 /index.php?id=1 Scanner 941100
XSS via libinjection
Detectat
2026-10-11 17:48:14 198.51.100.22 /.env XSS 932100
RCE — Unix commands
Detectat
2026-10-11 22:00:10 198.51.100.26 /wp-login.php SQL Injection 941100
XSS via libinjection
Detectat
2026-10-11 18:40:14 198.51.100.15 /xmlrpc.php Scanner 913100
Security scanner — User-Agent
Blocat
2026-10-11 17:04:52 198.51.100.30 /wp-login.php RCE 941100
XSS via libinjection
Detectat
2026-10-11 18:53:38 198.51.100.35 /index.php?id=1 XSS 941100
XSS via libinjection
Blocat
2026-10-11 14:13:38 198.51.100.33 /admin/ Protocol Attack 942100
SQL Injection via libinjection
Detectat
2026-10-11 16:13:00 198.51.100.22 /api/v1/login Protocol Attack 941100
XSS via libinjection
Detectat
2026-10-11 16:52:12 198.51.100.33 /api/v1/login Protocol Attack 942100
SQL Injection via libinjection
Detectat
2026-10-11 18:50:14 198.51.100.18 /wp-login.php RCE 913100
Security scanner — User-Agent
Blocat
2026-10-11 11:21:18 198.51.100.33 /?q=../../etc/passwd Protocol Attack 941100
XSS via libinjection
Detectat
2026-10-11 18:56:04 198.51.100.22 /admin/ XSS 942100
SQL Injection via libinjection
Blocat
2026-10-11 15:49:32 198.51.100.23 /admin/ Scanner 932100
RCE — Unix commands
Blocat
2026-10-11 11:40:06 198.51.100.19 /admin/ RCE 942100
SQL Injection via libinjection
Detectat
2026-10-11 08:49:50 198.51.100.18 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectat
2026-10-11 17:49:38 198.51.100.22 /admin/ SQL Injection 941100
XSS via libinjection
Detectat
2026-10-11 14:31:59 198.51.100.34 /.env LFI/Path Traversal 932100
RCE — Unix commands
Blocat
2026-10-11 20:06:54 198.51.100.19 /.env RCE 941100
XSS via libinjection
Detectat
2026-10-11 06:15:20 198.51.100.35 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Detectat
2026-10-11 05:41:32 198.51.100.15 /index.php?id=1 SQL Injection 913100
Security scanner — User-Agent
Detectat
2026-10-11 13:13:33 198.51.100.21 /index.php?id=1 XSS 941100
XSS via libinjection
Detectat
2026-10-11 18:39:02 198.51.100.35 /.env XSS 941100
XSS via libinjection
Detectat
2026-10-11 15:35:45 198.51.100.32 /xmlrpc.php LFI/Path Traversal 930100
Path Traversal (/../)
Blocat
2026-10-11 04:29:18 198.51.100.17 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Detectat
2026-10-11 04:31:08 198.51.100.22 /.env Scanner 930100
Path Traversal (/../)
Blocat
2026-10-11 06:53:18 198.51.100.24 /api/v1/login RCE 930100
Path Traversal (/../)
Detectat
2026-10-11 13:49:12 198.51.100.25 /xmlrpc.php RCE 932100
RCE — Unix commands
Detectat
2026-10-11 12:51:44 198.51.100.19 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectat
2026-10-11 01:02:56 198.51.100.17 /.env LFI/Path Traversal 913100
Security scanner — User-Agent
Detectat
2026-10-11 15:31:34 198.51.100.21 /.env RCE 930100
Path Traversal (/../)
Detectat
2026-10-11 07:19:23 198.51.100.18 /xmlrpc.php LFI/Path Traversal 942100
SQL Injection via libinjection
Blocat
2026-10-11 17:20:34 198.51.100.18 /api/v1/login XSS 942100
SQL Injection via libinjection
Detectat
2026-10-11 05:16:49 198.51.100.19 /xmlrpc.php Scanner 930100
Path Traversal (/../)
Detectat
2026-10-11 11:49:50 198.51.100.27 /wp-login.php SQL Injection 932100
RCE — Unix commands
Blocat
2026-10-11 11:11:03 198.51.100.18 /.env Scanner 913100
Security scanner — User-Agent
Blocat
2026-10-11 17:01:18 198.51.100.24 /.env SQL Injection 913100
Security scanner — User-Agent
Detectat
2026-10-11 02:58:20 198.51.100.12 /?q=../../etc/passwd RCE 941100
XSS via libinjection
Detectat
2026-10-11 04:50:38 198.51.100.27 /admin/ RCE 930100
Path Traversal (/../)
Detectat
2026-10-10 20:18:23 198.51.100.35 /xmlrpc.php RCE 942100
SQL Injection via libinjection
Detectat
2026-10-11 13:11:08 198.51.100.14 /api/v1/login Scanner 930100
Path Traversal (/../)
Detectat
2026-10-10 21:27:53 198.51.100.18 /.env Scanner 941100
XSS via libinjection
Detectat
2026-10-11 05:24:54 198.51.100.20 /api/v1/login RCE 941100
XSS via libinjection
Blocat
2026-10-11 04:43:14 198.51.100.13 /index.php?id=1 SQL Injection 930100
Path Traversal (/../)
Blocat
2026-10-11 13:27:16 198.51.100.23 /wp-login.php RCE 941100
XSS via libinjection
Detectat
2026-10-11 05:13:38 198.51.100.11 /wp-login.php XSS 930100
Path Traversal (/../)
Detectat
2026-10-11 18:40:38 198.51.100.31 /?q=../../etc/passwd SQL Injection 913100
Security scanner — User-Agent
Detectat
2026-10-10 15:00:16 198.51.100.21 /api/v1/login Scanner 932100
RCE — Unix commands
Detectat
2026-10-11 02:27:06 198.51.100.29 /xmlrpc.php LFI/Path Traversal 913100
Security scanner — User-Agent
Detectat
2026-10-10 15:27:56 198.51.100.14 /wp-login.php Protocol Attack 932100
RCE — Unix commands
Detectat
2026-10-10 14:33:34 198.51.100.35 /?q=../../etc/passwd Scanner 930100
Path Traversal (/../)
Blocat
2026-10-11 11:39:03 198.51.100.22 /?q=../../etc/passwd SQL Injection 930100
Path Traversal (/../)
Detectat
2026-10-11 17:35:08 198.51.100.24 /wp-login.php RCE 941100
XSS via libinjection
Detectat
2026-10-11 17:30:30 198.51.100.13 /index.php?id=1 LFI/Path Traversal 930100
Path Traversal (/../)
Blocat
2026-10-11 12:09:42 198.51.100.21 /index.php?id=1 RCE 930100
Path Traversal (/../)
Detectat
2026-10-10 13:52:14 198.51.100.32 /api/v1/login Scanner 942100
SQL Injection via libinjection
Detectat
2026-10-11 13:35:08 198.51.100.35 /.env Protocol Attack 913100
Security scanner — User-Agent
Detectat
2026-10-11 16:37:59 198.51.100.15 /index.php?id=1 XSS 930100
Path Traversal (/../)
Blocat
2026-10-11 11:39:02 198.51.100.25 /?q=../../etc/passwd Protocol Attack 932100
RCE — Unix commands
Detectat
2026-10-11 18:54:07 198.51.100.13 /.env Protocol Attack 932100
RCE — Unix commands
Blocat
2026-10-10 10:39:50 198.51.100.11 /api/v1/login LFI/Path Traversal 932100
RCE — Unix commands
Blocat
2026-10-11 09:52:08 198.51.100.16 /?q=../../etc/passwd RCE 913100
Security scanner — User-Agent
Blocat
2026-10-10 19:15:46 198.51.100.34 /admin/ SQL Injection 932100
RCE — Unix commands
Detectat
2026-10-10 20:40:57 198.51.100.28 /.env RCE 932100
RCE — Unix commands
Blocat
2026-10-11 04:09:02 198.51.100.13 /admin/ Protocol Attack 930100
Path Traversal (/../)
Detectat
2026-10-11 15:55:22 198.51.100.25 /admin/ SQL Injection 932100
RCE — Unix commands
Detectat
2026-10-10 15:17:18 198.51.100.28 /api/v1/login RCE 942100
SQL Injection via libinjection
Blocat
2026-10-10 10:33:38 198.51.100.30 /?q=../../etc/passwd Protocol Attack 930100
Path Traversal (/../)
Detectat
2026-10-10 16:43:40 198.51.100.27 /.env SQL Injection 930100
Path Traversal (/../)
Detectat
2026-10-11 05:59:47 198.51.100.20 /index.php?id=1 LFI/Path Traversal 942100
SQL Injection via libinjection
Detectat
2026-10-11 10:36:38 198.51.100.13 /index.php?id=1 Protocol Attack 930100
Path Traversal (/../)
Detectat
2026-10-11 11:12:28 198.51.100.31 /api/v1/login XSS 930100
Path Traversal (/../)
Blocat

Un ModSecurity log viewer pentru jurnalul de audit

ModSecurity împreună cu OWASP Core Rule Set blochează foarte mult și scrie despre aproape tot într-un jurnal de audit al cărui format a fost gândit pentru mașini. Pagina aceasta îl transformă în ceva lizibil: ce cereri au fost blocate, ce regulă s-a declanșat, care a fost scorul de anomalie și de unde a venit cererea.

Motivul pentru care merită să vă uitați aici regulat sunt fals-pozitivele. Core Rule Set este intenționat sever și, la nivelul implicit de paranoia, blochează trafic legitim în majoritatea aplicațiilor reale: încărcările de fișiere, editoarele de text formatat și tot ce trimite marcaje sau șiruri care seamănă cu SQL sunt victimele obișnuite. Tiparul de recunoscut este același identificator de regulă care se declanșează în mod repetat pe același punct final, venind de la multe adrese diferite. Nu e un atac, ci propria dumneavoastră aplicație care este prinsă.

Când găsiți un asemenea caz, păstrați excepția îngustă: excludeți exact acea regulă pentru exact acel parametru pe exact acea cale, niciodată regula întreagă și cu atât mai puțin întreaga categorie. Pagina listează și setul de reguli activ, ca să confirmați după o modificare ce este într-adevăr încărcat.