|
| 1 | +--622ca252-A-- |
| 2 | +[01/May/2018:08:05:00 +0200] WugN3pjbflCiqw4yEJ3nggAAAAk 172.16.0.2 22387 192.168.0.1 80 |
| 3 | +--622ca252-B-- |
| 4 | +GET /phpmyadmin/index.php HTTP/1.1 |
| 5 | +User-Agent: Mozilla/5.0 |
| 6 | +Host: 192.168.0.1 |
| 7 | +Connection: Keep-Alive |
| 8 | +Cache-Control: no-cache |
| 9 | + |
| 10 | +--622ca252-F-- |
| 11 | +HTTP/1.1 403 Forbidden |
| 12 | +Content-Length: 222 |
| 13 | +Keep-Alive: timeout=5, max=99 |
| 14 | +Connection: Keep-Alive |
| 15 | +Content-Type: text/html; charset=iso-8859-1 |
| 16 | + |
| 17 | +--622ca252-E-- |
| 18 | +<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> |
| 19 | +<html><head> |
| 20 | +<title>403 Forbidden</title> |
| 21 | +</head><body> |
| 22 | +<h1>Forbidden</h1> |
| 23 | +<p>You don't have permission to access /phpmyadmin/index.php |
| 24 | +on this server.</p> |
| 25 | +</body></html> |
| 26 | + |
| 27 | +--622ca252-H-- |
| 28 | +Message: Access denied with code 403 (phase 1). Pattern match "/phpmyadmin" at REQUEST_FILENAME. [file "/etc/httpd/conf.d/mod_security.conf"] [line "94"] [id "10000"] [msg "Blocking access to /phpmyadmin/index.php."] [tag "Blacklist Rules"] |
| 29 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.16.0.2] ModSecurity: Access denied with code 403 (phase 1). Pattern match "/phpmyadmin" at REQUEST_FILENAME. [file "/etc/httpd/conf.d/mod_security.conf"] [line "94"] [id "10000"] [msg "Blocking access to /phpmyadmin/index.php."] [tag "Blacklist Rules"] [hostname "192.168.0.1"] [uri "/phpmyadmin/index.php"] [unique_id "WugN3pjbflCiqw4yEJ3nggAAAAk"] |
| 30 | +Action: Intercepted (phase 1) |
| 31 | +Stopwatch: 1525157342927546 578 (- - -) |
| 32 | +Stopwatch2: 1525157342927546 578; combined=125, p1=53, p2=0, p3=0, p4=0, p5=72, sr=0, sw=0, l=0, gc=0 |
| 33 | +Response-Body-Transformed: Dechunked |
| 34 | +Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); OWASP_CRS/3.0.2. |
| 35 | +Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips |
| 36 | +Engine-Mode: "ENABLED" |
| 37 | + |
| 38 | +--622ca252-Z-- |
| 39 | + |
| 40 | +--68a39c63-A-- |
| 41 | +[01/May/2018:08:10:20 +0200] WvGgdU9AURJlp7Ta7HNRzAAAAAE 10.5.6.7 37346 192.168.0.1 443 |
| 42 | +--68a39c63-B-- |
| 43 | +GET /favicon.ico HTTP/1.1 |
| 44 | +Host: 192.168.0.1 |
| 45 | +Connection: keep-alive |
| 46 | +Accept-Encoding: gzip, deflate |
| 47 | +Accept: */* |
| 48 | +User-Agent: python-requests/2.13.0 |
| 49 | + |
| 50 | +--68a39c63-F-- |
| 51 | +HTTP/1.1 404 Not Found |
| 52 | +Content-Length: 209 |
| 53 | +Keep-Alive: timeout=5, max=100 |
| 54 | +Connection: Keep-Alive |
| 55 | +Content-Type: text/html; charset=iso-8859-1 |
| 56 | + |
| 57 | +--68a39c63-E-- |
| 58 | +<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> |
| 59 | +<html><head> |
| 60 | +<title>404 Not Found</title> |
| 61 | +</head><body> |
| 62 | +<h1>Not Found</h1> |
| 63 | +<p>The requested URL /favicon.ico was not found on this server.</p> |
| 64 | +</body></html> |
| 65 | + |
| 66 | +--68a39c63-H-- |
| 67 | +Message: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/httpd/conf.d/crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "164"] [id "913101"] [rev "1"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.13.0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS/AUTOMATION/SCRIPTING"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] |
| 68 | +Message: Warning. Pattern match "^[\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] |
| 69 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 10.5.6.7] ModSecurity: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/httpd/conf.d/crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "164"] [id "913101"] [rev "1"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.13.0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS/AUTOMATION/SCRIPTING"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "192.168.0.1"] [uri "/favicon.ico"] [unique_id "WvGgdU9AURJlp7Ta7HNRzAAAAAE"] |
| 70 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 10.5.6.7] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "192.168.0.1"] [uri "/favicon.ico"] [unique_id "WvGgdU9AURJlp7Ta7HNRzAAAAAE"] |
| 71 | +Stopwatch: 1525784693307805 2777 (- - -) |
| 72 | +Stopwatch2: 1525784693307805 2777; combined=2021, p1=694, p2=748, p3=58, p4=209, p5=224, sr=328, sw=88, l=0, gc=0 |
| 73 | +Response-Body-Transformed: Dechunked |
| 74 | +Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); OWASP_CRS/3.0.2. |
| 75 | +Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips |
| 76 | +Engine-Mode: "ENABLED" |
| 77 | + |
| 78 | +--68a39c63-Z-- |
| 79 | + |
| 80 | + |
| 81 | +--c2578d7b-A-- |
| 82 | +[05/May/2018:03:30:12 +0200] WvTyJHKtCFt-nNhJ4VGG9QAAAAg 172.16.0.2 45736 192.168.0.1 443 |
| 83 | +--c2578d7b-B-- |
| 84 | +HEAD /index.php HTTP/1.1 |
| 85 | +Host: 192.168.0.1 |
| 86 | +Accept: */* |
| 87 | +Accept-Encoding: gzip, deflate |
| 88 | +User-Agent: python-requests/2.18.4 |
| 89 | +Connection: keep-alive |
| 90 | + |
| 91 | +--c2578d7b-F-- |
| 92 | +HTTP/1.1 404 Not Found |
| 93 | +Keep-Alive: timeout=5, max=100 |
| 94 | +Connection: Keep-Alive |
| 95 | +Content-Type: text/html; charset=iso-8859-1 |
| 96 | + |
| 97 | +--c2578d7b-E-- |
| 98 | + |
| 99 | +--c2578d7b-H-- |
| 100 | +Message: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/httpd/conf.d/crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "164"] [id "913101"] [rev "1"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.18.4"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS/AUTOMATION/SCRIPTING"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] |
| 101 | +Message: Warning. Pattern match "^[\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] |
| 102 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.16.0.2] ModSecurity: Warning. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/httpd/conf.d/crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "164"] [id "913101"] [rev "1"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.18.4"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS/AUTOMATION/SCRIPTING"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "192.168.0.1"] [uri "/index.php"] [unique_id "WvTyJHKtCFt-nNhJ4VGG9QAAAAg"] |
| 103 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.16.0.2] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "192.168.0.1"] [uri "/index.php"] [unique_id "WvTyJHKtCFt-nNhJ4VGG9QAAAAg"] |
| 104 | +Stopwatch: 1526002212715379 3565 (- - -) |
| 105 | +Stopwatch2: 1526002212715379 3565; combined=2244, p1=885, p2=860, p3=66, p4=119, p5=214, sr=539, sw=100, l=0, gc=0 |
| 106 | +Response-Body-Transformed: Dechunked |
| 107 | +Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); OWASP_CRS/3.0.2. |
| 108 | +Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips |
| 109 | +Engine-Mode: "ENABLED" |
| 110 | + |
| 111 | +--c2578d7b-Z-- |
| 112 | + |
| 113 | +--7b0b0a73-A-- |
| 114 | +[09/May/2018:09:09:53 +0200] Wu0TYfl141Zko07xKZQLRwAAAAI 10.9.8.7 54171 192.168.0.1 443 |
| 115 | +--7b0b0a73-B-- |
| 116 | +GET /verifylogin.do HTTP/1.1 |
| 117 | +Connection: Keep-Alive |
| 118 | +Content-Type: %{(#test='multipart/form-data').(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.println(55*55+1)).(#ros.flush())} |
| 119 | +Accept: */* |
| 120 | +Accept-Language: zh-cn |
| 121 | +Referer: https://192.168.0.1:443/verifylogin.do |
| 122 | +User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1) |
| 123 | +Host: 192.168.0.1 |
| 124 | + |
| 125 | +--7b0b0a73-F-- |
| 126 | +HTTP/1.1 404 Not Found |
| 127 | +Content-Length: 212 |
| 128 | +Keep-Alive: timeout=5, max=100 |
| 129 | +Connection: Keep-Alive |
| 130 | +Content-Type: text/html; charset=iso-8859-1 |
| 131 | + |
| 132 | +--7b0b0a73-E-- |
| 133 | +<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> |
| 134 | +<html><head> |
| 135 | +<title>404 Not Found</title> |
| 136 | +</head><body> |
| 137 | +<h1>Not Found</h1> |
| 138 | +<p>The requested URL /verifylogin.do was not found on this server.</p> |
| 139 | +</body></html> |
| 140 | + |
| 141 | +--7b0b0a73-H-- |
| 142 | +Message: Warning. Pattern match "^[\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] |
| 143 | +Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 10.9.8.7] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/conf.d/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "810"] [id "920350"] [rev "2"] [msg "Host header is a numeric IP address"] [data "192.168.0.1"] [severity "WARNING"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "192.168.0.1"] [uri "/verifylogin.do"] [unique_id "Wu0TYfl141Zko07xKZQLRwAAAAI"] |
| 144 | +Stopwatch: 1525486433569262 3185 (- - -) |
| 145 | +Stopwatch2: 1525486433569262 3185; combined=1985, p1=810, p2=812, p3=56, p4=191, p5=115, sr=399, sw=1, l=0, gc=0 |
| 146 | +Response-Body-Transformed: Dechunked |
| 147 | +Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); OWASP_CRS/3.0.2. |
| 148 | +Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips |
| 149 | +Engine-Mode: "ENABLED" |
| 150 | + |
| 151 | + |
| 152 | +--7b0b0a73-Z-- |
0 commit comments