3163 lines
142 KiB
Plaintext
3163 lines
142 KiB
Plaintext
---IrHNKUDO---A--
|
|
[16/Jun/2025:05:36:08 +0000] 175005216849.844682 172.19.0.1 45454 172.19.0.2 443
|
|
---IrHNKUDO---B--
|
|
GET / HTTP/1.1
|
|
Host: localhost:8443
|
|
User-Agent: curl/7.81.0
|
|
Accept: */*
|
|
|
|
---IrHNKUDO---D--
|
|
|
|
---IrHNKUDO---F--
|
|
HTTP/1.1 403
|
|
|
|
---IrHNKUDO---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Contains' with parameter `curl' against variable `REQUEST_HEADERS:User-Agent' (Value: `curl/7.81.0' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "1"] [id "999001"] [rev ""] [msg "Blocked curl request"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005216849.844682"] [ref "o0,4v48,11"]
|
|
|
|
---IrHNKUDO---I--
|
|
|
|
---IrHNKUDO---J--
|
|
|
|
---IrHNKUDO---Z--
|
|
|
|
---cI5in2Az---A--
|
|
[16/Jun/2025:05:46:05 +0000] 175005276597.127114 103.250.147.78 60510 172.19.0.2 443
|
|
---cI5in2Az---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---cI5in2Az---D--
|
|
|
|
---cI5in2Az---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---cI5in2Az---F--
|
|
HTTP/1.1 200
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 05:46:05 GMT
|
|
Content-Length: 615
|
|
Content-Type: text/html
|
|
Last-Modified: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Connection: keep-alive
|
|
ETag: "684fad23-267"
|
|
|
|
---cI5in2Az---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005276597.127114"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---cI5in2Az---I--
|
|
|
|
---cI5in2Az---J--
|
|
|
|
---cI5in2Az---Z--
|
|
|
|
---wx0FSLeF---A--
|
|
[16/Jun/2025:05:46:05 +0000] 175005276587.546540 103.250.147.78 60510 172.19.0.2 443
|
|
---wx0FSLeF---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---wx0FSLeF---D--
|
|
|
|
---wx0FSLeF---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx/1.24.0</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---wx0FSLeF---F--
|
|
HTTP/1.1 404
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 05:46:05 GMT
|
|
Content-Length: 153
|
|
Content-Type: text/html
|
|
Connection: keep-alive
|
|
|
|
---wx0FSLeF---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005276587.546540"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---wx0FSLeF---I--
|
|
|
|
---wx0FSLeF---J--
|
|
|
|
---wx0FSLeF---Z--
|
|
|
|
---YKWidTE4---A--
|
|
[16/Jun/2025:05:46:12 +0000] 175005277285.130394 172.19.0.1 41534 172.19.0.2 443
|
|
---YKWidTE4---B--
|
|
GET / HTTP/1.1
|
|
Host: localhost:8443
|
|
User-Agent: curl/7.81.0
|
|
Accept: */*
|
|
|
|
---YKWidTE4---D--
|
|
|
|
---YKWidTE4---F--
|
|
HTTP/1.1 403
|
|
|
|
---YKWidTE4---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Contains' with parameter `curl' against variable `REQUEST_HEADERS:User-Agent' (Value: `curl/7.81.0' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "1"] [id "999001"] [rev ""] [msg "Blocked curl request"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005277285.130394"] [ref "o0,4v48,11"]
|
|
|
|
---YKWidTE4---I--
|
|
|
|
---YKWidTE4---J--
|
|
|
|
---YKWidTE4---Z--
|
|
|
|
---wIbLZyjL---A--
|
|
[16/Jun/2025:05:46:17 +0000] 175005277734.297664 103.250.147.78 60510 172.19.0.2 443
|
|
---wIbLZyjL---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fad23-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Priority: u=0, i
|
|
|
|
---wIbLZyjL---D--
|
|
|
|
---wIbLZyjL---F--
|
|
HTTP/1.1 304
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 05:46:17 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Connection: keep-alive
|
|
ETag: "684fad23-267"
|
|
|
|
---wIbLZyjL---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005277734.297664"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---wIbLZyjL---I--
|
|
|
|
---wIbLZyjL---J--
|
|
|
|
---wIbLZyjL---Z--
|
|
|
|
---ZAQJALK7---A--
|
|
[16/Jun/2025:05:47:17 +0000] 175005283786.473028 103.250.147.78 60510 172.19.0.2 443
|
|
---ZAQJALK7---B--
|
|
GET /?testparam=test%22 HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---ZAQJALK7---D--
|
|
|
|
---ZAQJALK7---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx/1.24.0</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---ZAQJALK7---F--
|
|
HTTP/1.1 403
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 05:47:17 GMT
|
|
Content-Length: 153
|
|
Content-Type: text/html
|
|
Connection: keep-alive
|
|
|
|
---ZAQJALK7---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005283786.473028"] [ref "o0,18o0,13o13,5v39,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test"' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005283786.473028"] [ref "o0,4v16,5"]
|
|
|
|
---ZAQJALK7---I--
|
|
|
|
---ZAQJALK7---J--
|
|
|
|
---ZAQJALK7---Z--
|
|
|
|
---qfKUWrM8---A--
|
|
[16/Jun/2025:05:47:34 +0000] 175005285435.440299 103.250.147.78 60510 172.19.0.2 443
|
|
---qfKUWrM8---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fad23-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Priority: u=0, i
|
|
|
|
---qfKUWrM8---D--
|
|
|
|
---qfKUWrM8---F--
|
|
HTTP/1.1 304
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 05:47:34 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Connection: keep-alive
|
|
ETag: "684fad23-267"
|
|
|
|
---qfKUWrM8---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005285435.440299"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---qfKUWrM8---I--
|
|
|
|
---qfKUWrM8---J--
|
|
|
|
---qfKUWrM8---Z--
|
|
|
|
---dwstAwc3---A--
|
|
[16/Jun/2025:05:57:26 +0000] 175005344675.143932 103.250.147.78 60537 172.19.0.2 443
|
|
---dwstAwc3---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fad23-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 05:35:31 GMT
|
|
Priority: u=0, i
|
|
|
|
---dwstAwc3---D--
|
|
|
|
---dwstAwc3---F--
|
|
HTTP/1.1 403
|
|
|
|
---dwstAwc3---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005344675.143932"] [ref "o0,1v4,1"]
|
|
|
|
---dwstAwc3---I--
|
|
|
|
---dwstAwc3---J--
|
|
|
|
---dwstAwc3---Z--
|
|
|
|
---GjBMH9Bo---A--
|
|
[16/Jun/2025:05:57:26 +0000] 175005344660.625979 103.250.147.78 60537 172.19.0.2 443
|
|
---GjBMH9Bo---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---GjBMH9Bo---D--
|
|
|
|
---GjBMH9Bo---F--
|
|
HTTP/1.1 403
|
|
|
|
---GjBMH9Bo---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005344660.625979"] [ref "o0,12v4,12"]
|
|
|
|
---GjBMH9Bo---I--
|
|
|
|
---GjBMH9Bo---J--
|
|
|
|
---GjBMH9Bo---Z--
|
|
|
|
---cRwGs9XN---A--
|
|
[16/Jun/2025:05:57:28 +0000] 175005344819.769882 103.250.147.78 60538 172.19.0.2 443
|
|
---cRwGs9XN---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---cRwGs9XN---D--
|
|
|
|
---cRwGs9XN---F--
|
|
HTTP/1.1 403
|
|
|
|
---cRwGs9XN---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005344819.769882"] [ref "o0,1v4,1"]
|
|
|
|
---cRwGs9XN---I--
|
|
|
|
---cRwGs9XN---J--
|
|
|
|
---cRwGs9XN---Z--
|
|
|
|
---5AKcdHS3---A--
|
|
[16/Jun/2025:05:57:28 +0000] 175005344826.350732 103.250.147.78 60538 172.19.0.2 443
|
|
---5AKcdHS3---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---5AKcdHS3---D--
|
|
|
|
---5AKcdHS3---F--
|
|
HTTP/1.1 403
|
|
|
|
---5AKcdHS3---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005344826.350732"] [ref "o0,12v4,12"]
|
|
|
|
---5AKcdHS3---I--
|
|
|
|
---5AKcdHS3---J--
|
|
|
|
---5AKcdHS3---Z--
|
|
|
|
---YuaDsIPQ---A--
|
|
[16/Jun/2025:05:57:31 +0000] 175005345168.922966 103.250.147.78 60543 172.19.0.2 443
|
|
---YuaDsIPQ---B--
|
|
GET //api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---YuaDsIPQ---D--
|
|
|
|
---YuaDsIPQ---F--
|
|
HTTP/1.1 403
|
|
|
|
---YuaDsIPQ---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `//api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "//api"] [unique_id "175005345168.922966"] [ref "o0,5v4,5"]
|
|
|
|
---YuaDsIPQ---I--
|
|
|
|
---YuaDsIPQ---J--
|
|
|
|
---YuaDsIPQ---Z--
|
|
|
|
---cqS9zAPC---A--
|
|
[16/Jun/2025:05:57:50 +0000] 175005347049.210812 103.250.147.78 60543 172.19.0.2 443
|
|
---cqS9zAPC---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---cqS9zAPC---D--
|
|
|
|
---cqS9zAPC---F--
|
|
HTTP/1.1 403
|
|
|
|
---cqS9zAPC---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005347049.210812"] [ref "o0,4v4,4"]
|
|
|
|
---cqS9zAPC---I--
|
|
|
|
---cqS9zAPC---J--
|
|
|
|
---cqS9zAPC---Z--
|
|
|
|
---1nR7DrxW---A--
|
|
[16/Jun/2025:05:57:50 +0000] 175005347052.600884 103.250.147.78 60543 172.19.0.2 443
|
|
---1nR7DrxW---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/api
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---1nR7DrxW---D--
|
|
|
|
---1nR7DrxW---F--
|
|
HTTP/1.1 403
|
|
|
|
---1nR7DrxW---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005347052.600884"] [ref "o0,12v4,12"]
|
|
|
|
---1nR7DrxW---I--
|
|
|
|
---1nR7DrxW---J--
|
|
|
|
---1nR7DrxW---Z--
|
|
|
|
---LDYUnbRg---A--
|
|
[16/Jun/2025:05:58:34 +0000] 175005351476.885429 103.250.147.78 60544 172.19.0.2 443
|
|
---LDYUnbRg---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---LDYUnbRg---D--
|
|
|
|
---LDYUnbRg---F--
|
|
HTTP/1.1 403
|
|
|
|
---LDYUnbRg---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005351476.885429"] [ref "o0,4v4,4"]
|
|
|
|
---LDYUnbRg---I--
|
|
|
|
---LDYUnbRg---J--
|
|
|
|
---LDYUnbRg---Z--
|
|
|
|
---mYsIFw3m---A--
|
|
[16/Jun/2025:05:58:34 +0000] 175005351417.182151 103.250.147.78 60544 172.19.0.2 443
|
|
---mYsIFw3m---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/api
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---mYsIFw3m---D--
|
|
|
|
---mYsIFw3m---F--
|
|
HTTP/1.1 403
|
|
|
|
---mYsIFw3m---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005351417.182151"] [ref "o0,12v4,12"]
|
|
|
|
---mYsIFw3m---I--
|
|
|
|
---mYsIFw3m---J--
|
|
|
|
---mYsIFw3m---Z--
|
|
|
|
---tGQHhJXh---A--
|
|
[16/Jun/2025:06:02:33 +0000] 175005375350.206712 103.250.147.78 60559 172.19.0.2 443
|
|
---tGQHhJXh---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---tGQHhJXh---D--
|
|
|
|
---tGQHhJXh---F--
|
|
HTTP/1.1 403
|
|
|
|
---tGQHhJXh---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005375350.206712"] [ref "o0,4v4,4"]
|
|
|
|
---tGQHhJXh---I--
|
|
|
|
---tGQHhJXh---J--
|
|
|
|
---tGQHhJXh---Z--
|
|
|
|
---mQwOS2x7---A--
|
|
[16/Jun/2025:06:02:33 +0000] 175005375393.658231 103.250.147.78 60559 172.19.0.2 443
|
|
---mQwOS2x7---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/api
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---mQwOS2x7---D--
|
|
|
|
---mQwOS2x7---F--
|
|
HTTP/1.1 403
|
|
|
|
---mQwOS2x7---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005375393.658231"] [ref "o0,12v4,12"]
|
|
|
|
---mQwOS2x7---I--
|
|
|
|
---mQwOS2x7---J--
|
|
|
|
---mQwOS2x7---Z--
|
|
|
|
---UKxiGDuu---A--
|
|
[16/Jun/2025:06:02:36 +0000] 175005375672.427890 103.250.147.78 60560 172.19.0.2 443
|
|
---UKxiGDuu---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---UKxiGDuu---D--
|
|
|
|
---UKxiGDuu---F--
|
|
HTTP/1.1 403
|
|
|
|
---UKxiGDuu---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005375672.427890"] [ref "o0,4v4,4"]
|
|
|
|
---UKxiGDuu---I--
|
|
|
|
---UKxiGDuu---J--
|
|
|
|
---UKxiGDuu---Z--
|
|
|
|
---rI1260HD---A--
|
|
[16/Jun/2025:06:02:36 +0000] 175005375680.813462 103.250.147.78 60560 172.19.0.2 443
|
|
---rI1260HD---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/api
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---rI1260HD---D--
|
|
|
|
---rI1260HD---F--
|
|
HTTP/1.1 403
|
|
|
|
---rI1260HD---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005375680.813462"] [ref "o0,12v4,12"]
|
|
|
|
---rI1260HD---I--
|
|
|
|
---rI1260HD---J--
|
|
|
|
---rI1260HD---Z--
|
|
|
|
---vs2KCaUG---A--
|
|
[16/Jun/2025:06:02:37 +0000] 175005375729.579352 103.250.147.78 60561 172.19.0.2 443
|
|
---vs2KCaUG---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---vs2KCaUG---D--
|
|
|
|
---vs2KCaUG---F--
|
|
HTTP/1.1 403
|
|
|
|
---vs2KCaUG---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005375729.579352"] [ref "o0,4v4,4"]
|
|
|
|
---vs2KCaUG---I--
|
|
|
|
---vs2KCaUG---J--
|
|
|
|
---vs2KCaUG---Z--
|
|
|
|
---EOB3zrfP---A--
|
|
[16/Jun/2025:06:03:03 +0000] 175005378386.469966 103.250.147.78 60561 172.19.0.2 443
|
|
---EOB3zrfP---B--
|
|
GET /api HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---EOB3zrfP---D--
|
|
|
|
---EOB3zrfP---F--
|
|
HTTP/1.1 403
|
|
|
|
---EOB3zrfP---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/api' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/api"] [unique_id "175005378386.469966"] [ref "o0,4v4,4"]
|
|
|
|
---EOB3zrfP---I--
|
|
|
|
---EOB3zrfP---J--
|
|
|
|
---EOB3zrfP---Z--
|
|
|
|
---GXyRP1Ka---A--
|
|
[16/Jun/2025:06:03:04 +0000] 17500537844.310570 103.250.147.78 60561 172.19.0.2 443
|
|
---GXyRP1Ka---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/api
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---GXyRP1Ka---D--
|
|
|
|
---GXyRP1Ka---F--
|
|
HTTP/1.1 403
|
|
|
|
---GXyRP1Ka---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "17500537844.310570"] [ref "o0,12v4,12"]
|
|
|
|
---GXyRP1Ka---I--
|
|
|
|
---GXyRP1Ka---J--
|
|
|
|
---GXyRP1Ka---Z--
|
|
|
|
---XVwNpWtx---A--
|
|
[16/Jun/2025:06:03:07 +0000] 175005378756.114459 103.250.147.78 60564 172.19.0.2 443
|
|
---XVwNpWtx---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---XVwNpWtx---D--
|
|
|
|
---XVwNpWtx---F--
|
|
HTTP/1.1 403
|
|
|
|
---XVwNpWtx---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005378756.114459"] [ref "o0,1v4,1"]
|
|
|
|
---XVwNpWtx---I--
|
|
|
|
---XVwNpWtx---J--
|
|
|
|
---XVwNpWtx---Z--
|
|
|
|
---upsrDxyp---A--
|
|
[16/Jun/2025:06:03:15 +0000] 175005379574.344754 103.250.147.78 60564 172.19.0.2 443
|
|
---upsrDxyp---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---upsrDxyp---D--
|
|
|
|
---upsrDxyp---F--
|
|
HTTP/1.1 403
|
|
|
|
---upsrDxyp---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005379574.344754"] [ref "o0,1v4,1"]
|
|
|
|
---upsrDxyp---I--
|
|
|
|
---upsrDxyp---J--
|
|
|
|
---upsrDxyp---Z--
|
|
|
|
---EReEFZl8---A--
|
|
[16/Jun/2025:06:03:15 +0000] 175005379590.829467 103.250.147.78 60564 172.19.0.2 443
|
|
---EReEFZl8---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---EReEFZl8---D--
|
|
|
|
---EReEFZl8---F--
|
|
HTTP/1.1 403
|
|
|
|
---EReEFZl8---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005379590.829467"] [ref "o0,12v4,12"]
|
|
|
|
---EReEFZl8---I--
|
|
|
|
---EReEFZl8---J--
|
|
|
|
---EReEFZl8---Z--
|
|
|
|
---QniNy1Bm---A--
|
|
[16/Jun/2025:06:03:52 +0000] 175005383255.337068 103.250.147.78 60567 172.19.0.2 443
|
|
---QniNy1Bm---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---QniNy1Bm---D--
|
|
|
|
---QniNy1Bm---F--
|
|
HTTP/1.1 403
|
|
|
|
---QniNy1Bm---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005383255.337068"] [ref "o0,1v4,1"]
|
|
|
|
---QniNy1Bm---I--
|
|
|
|
---QniNy1Bm---J--
|
|
|
|
---QniNy1Bm---Z--
|
|
|
|
---IWiMqXPv---A--
|
|
[16/Jun/2025:06:03:53 +0000] 175005383372.517662 103.250.147.78 60567 172.19.0.2 443
|
|
---IWiMqXPv---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---IWiMqXPv---D--
|
|
|
|
---IWiMqXPv---F--
|
|
HTTP/1.1 403
|
|
|
|
---IWiMqXPv---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005383372.517662"] [ref "o0,12v4,12"]
|
|
|
|
---IWiMqXPv---I--
|
|
|
|
---IWiMqXPv---J--
|
|
|
|
---IWiMqXPv---Z--
|
|
|
|
---WbBdunxr---A--
|
|
[16/Jun/2025:06:03:54 +0000] 175005383457.283759 103.250.147.78 60568 172.19.0.2 443
|
|
---WbBdunxr---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---WbBdunxr---D--
|
|
|
|
---WbBdunxr---F--
|
|
HTTP/1.1 403
|
|
|
|
---WbBdunxr---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005383457.283759"] [ref "o0,1v4,1"]
|
|
|
|
---WbBdunxr---I--
|
|
|
|
---WbBdunxr---J--
|
|
|
|
---WbBdunxr---Z--
|
|
|
|
---3AugNZM5---A--
|
|
[16/Jun/2025:06:03:54 +0000] 175005383429.928904 103.250.147.78 60568 172.19.0.2 443
|
|
---3AugNZM5---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---3AugNZM5---D--
|
|
|
|
---3AugNZM5---F--
|
|
HTTP/1.1 403
|
|
|
|
---3AugNZM5---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005383429.928904"] [ref "o0,12v4,12"]
|
|
|
|
---3AugNZM5---I--
|
|
|
|
---3AugNZM5---J--
|
|
|
|
---3AugNZM5---Z--
|
|
|
|
---VCDFO8WC---A--
|
|
[16/Jun/2025:06:04:23 +0000] 175005386322.040565 103.250.147.78 60569 172.19.0.2 443
|
|
---VCDFO8WC---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---VCDFO8WC---D--
|
|
|
|
---VCDFO8WC---F--
|
|
HTTP/1.1 403
|
|
|
|
---VCDFO8WC---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005386322.040565"] [ref "o0,1v4,1"]
|
|
|
|
---VCDFO8WC---I--
|
|
|
|
---VCDFO8WC---J--
|
|
|
|
---VCDFO8WC---Z--
|
|
|
|
---Lncxbews---A--
|
|
[16/Jun/2025:06:04:23 +0000] 175005386312.139663 103.250.147.78 60569 172.19.0.2 443
|
|
---Lncxbews---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---Lncxbews---D--
|
|
|
|
---Lncxbews---F--
|
|
HTTP/1.1 403
|
|
|
|
---Lncxbews---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005386312.139663"] [ref "o0,12v4,12"]
|
|
|
|
---Lncxbews---I--
|
|
|
|
---Lncxbews---J--
|
|
|
|
---Lncxbews---Z--
|
|
|
|
---037wAVWE---A--
|
|
[16/Jun/2025:06:04:25 +0000] 175005386582.899222 103.250.147.78 60570 172.19.0.2 443
|
|
---037wAVWE---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---037wAVWE---D--
|
|
|
|
---037wAVWE---F--
|
|
HTTP/1.1 403
|
|
|
|
---037wAVWE---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005386582.899222"] [ref "o0,1v4,1"]
|
|
|
|
---037wAVWE---I--
|
|
|
|
---037wAVWE---J--
|
|
|
|
---037wAVWE---Z--
|
|
|
|
---MD9qGsLZ---A--
|
|
[16/Jun/2025:06:04:25 +0000] 175005386586.947902 103.250.147.78 60570 172.19.0.2 443
|
|
---MD9qGsLZ---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---MD9qGsLZ---D--
|
|
|
|
---MD9qGsLZ---F--
|
|
HTTP/1.1 403
|
|
|
|
---MD9qGsLZ---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005386586.947902"] [ref "o0,12v4,12"]
|
|
|
|
---MD9qGsLZ---I--
|
|
|
|
---MD9qGsLZ---J--
|
|
|
|
---MD9qGsLZ---Z--
|
|
|
|
---51n19TYZ---A--
|
|
[16/Jun/2025:06:04:27 +0000] 175005386720.310769 103.250.147.78 60572 172.19.0.2 443
|
|
---51n19TYZ---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---51n19TYZ---D--
|
|
|
|
---51n19TYZ---F--
|
|
HTTP/1.1 403
|
|
|
|
---51n19TYZ---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005386720.310769"] [ref "o0,1v4,1"]
|
|
|
|
---51n19TYZ---I--
|
|
|
|
---51n19TYZ---J--
|
|
|
|
---51n19TYZ---Z--
|
|
|
|
---kUB2Va0e---A--
|
|
[16/Jun/2025:06:04:33 +0000] 175005387325.714459 103.250.147.78 60572 172.19.0.2 443
|
|
---kUB2Va0e---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---kUB2Va0e---D--
|
|
|
|
---kUB2Va0e---F--
|
|
HTTP/1.1 403
|
|
|
|
---kUB2Va0e---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005387325.714459"] [ref "o0,1v4,1"]
|
|
|
|
---kUB2Va0e---I--
|
|
|
|
---kUB2Va0e---J--
|
|
|
|
---kUB2Va0e---Z--
|
|
|
|
---RJlm0Mpg---A--
|
|
[16/Jun/2025:06:08:22 +0000] 175005410282.280721 103.250.147.78 60588 172.19.0.2 443
|
|
---RJlm0Mpg---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---RJlm0Mpg---D--
|
|
|
|
---RJlm0Mpg---F--
|
|
HTTP/1.1 403
|
|
|
|
---RJlm0Mpg---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005410282.280721"] [ref "o0,1v4,1"]
|
|
|
|
---RJlm0Mpg---I--
|
|
|
|
---RJlm0Mpg---J--
|
|
|
|
---RJlm0Mpg---Z--
|
|
|
|
---TVntCo6j---A--
|
|
[16/Jun/2025:06:08:22 +0000] 175005410253.580301 103.250.147.78 60588 172.19.0.2 443
|
|
---TVntCo6j---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---TVntCo6j---D--
|
|
|
|
---TVntCo6j---F--
|
|
HTTP/1.1 403
|
|
|
|
---TVntCo6j---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005410253.580301"] [ref "o0,12v4,12"]
|
|
|
|
---TVntCo6j---I--
|
|
|
|
---TVntCo6j---J--
|
|
|
|
---TVntCo6j---Z--
|
|
|
|
---1zQAjgA3---A--
|
|
[16/Jun/2025:06:08:23 +0000] 175005410341.332747 103.250.147.78 60589 172.19.0.2 443
|
|
---1zQAjgA3---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Cache-Control: no-cache
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
Pragma: no-cache
|
|
|
|
---1zQAjgA3---D--
|
|
|
|
---1zQAjgA3---F--
|
|
HTTP/1.1 403
|
|
|
|
---1zQAjgA3---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005410341.332747"] [ref "o0,1v4,1"]
|
|
|
|
---1zQAjgA3---I--
|
|
|
|
---1zQAjgA3---J--
|
|
|
|
---1zQAjgA3---Z--
|
|
|
|
---zaDxDoTJ---A--
|
|
[16/Jun/2025:06:08:23 +0000] 175005410375.277233 103.250.147.78 60589 172.19.0.2 443
|
|
---zaDxDoTJ---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Sec-Fetch-Site: same-origin
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Referer: https://13.234.29.148:8443/
|
|
Pragma: no-cache
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: no-cors
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Cache-Control: no-cache
|
|
Priority: u=6
|
|
Sec-Fetch-Dest: image
|
|
Host: 13.234.29.148:8443
|
|
|
|
---zaDxDoTJ---D--
|
|
|
|
---zaDxDoTJ---F--
|
|
HTTP/1.1 403
|
|
|
|
---zaDxDoTJ---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/favicon.ico' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005410375.277233"] [ref "o0,12v4,12"]
|
|
|
|
---zaDxDoTJ---I--
|
|
|
|
---zaDxDoTJ---J--
|
|
|
|
---zaDxDoTJ---Z--
|
|
|
|
---XwAgOsFJ---A--
|
|
[16/Jun/2025:06:08:37 +0000] 175005411768.545581 103.250.147.78 60589 172.19.0.2 443
|
|
---XwAgOsFJ---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---XwAgOsFJ---D--
|
|
|
|
---XwAgOsFJ---F--
|
|
HTTP/1.1 403
|
|
|
|
---XwAgOsFJ---H--
|
|
ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `^/(?!healthz|api/).*' against variable `REQUEST_URI' (Value: `/' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "9"] [id "900003"] [rev ""] [msg "Restricted access to non-API route"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005411768.545581"] [ref "o0,1v4,1"]
|
|
|
|
---XwAgOsFJ---I--
|
|
|
|
---XwAgOsFJ---J--
|
|
|
|
---XwAgOsFJ---Z--
|
|
|
|
---LidL9aTf---A--
|
|
[16/Jun/2025:06:13:04 +0000] 175005438418.830628 103.250.147.78 60613 172.19.0.2 443
|
|
---LidL9aTf---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---LidL9aTf---D--
|
|
|
|
---LidL9aTf---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---LidL9aTf---F--
|
|
HTTP/1.1 200
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 06:13:04 GMT
|
|
Content-Length: 615
|
|
Content-Type: text/html
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
Connection: keep-alive
|
|
ETag: "684fb233-267"
|
|
|
|
---LidL9aTf---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005438418.830628"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---LidL9aTf---I--
|
|
|
|
---LidL9aTf---J--
|
|
|
|
---LidL9aTf---Z--
|
|
|
|
---pXmAhebe---A--
|
|
[16/Jun/2025:06:13:04 +0000] 175005438453.245246 103.250.147.78 60613 172.19.0.2 443
|
|
---pXmAhebe---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Connection: keep-alive
|
|
Referer: https://13.234.29.148:8443/
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---pXmAhebe---D--
|
|
|
|
---pXmAhebe---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx/1.24.0</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---pXmAhebe---F--
|
|
HTTP/1.1 404
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 06:13:04 GMT
|
|
Content-Length: 153
|
|
Content-Type: text/html
|
|
Connection: keep-alive
|
|
|
|
---pXmAhebe---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005438453.245246"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---pXmAhebe---I--
|
|
|
|
---pXmAhebe---J--
|
|
|
|
---pXmAhebe---Z--
|
|
|
|
---WmxhDwPg---A--
|
|
[16/Jun/2025:06:14:42 +0000] 175005448270.247321 103.250.147.78 60616 172.19.0.2 443
|
|
---WmxhDwPg---B--
|
|
GET //?q=select+*+from+users HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---WmxhDwPg---D--
|
|
|
|
---WmxhDwPg---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx/1.24.0</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---WmxhDwPg---F--
|
|
HTTP/1.1 403
|
|
Server: nginx/1.24.0
|
|
Date: Mon, 16 Jun 2025 06:14:42 GMT
|
|
Content-Length: 153
|
|
Content-Type: text/html
|
|
Connection: keep-alive
|
|
|
|
---WmxhDwPg---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "//"] [unique_id "175005448270.247321"] [ref "o0,18o0,13o13,5v44,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Rx' with parameter `(?i)(union(.*?)select|select.+from)' against variable `ARGS:q' (Value: `select * from users' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "10"] [id "10003"] [rev ""] [msg "SQLi pattern blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "//"] [unique_id "175005448270.247321"] [ref "o0,13o0,13v9,19"]
|
|
|
|
---WmxhDwPg---I--
|
|
|
|
---WmxhDwPg---J--
|
|
|
|
---WmxhDwPg---Z--
|
|
|
|
---7ILerWwr---A--
|
|
[16/Jun/2025:06:55:19 +0000] 175005691988.041943 103.250.147.78 60856 172.19.0.2 443
|
|
---7ILerWwr---B--
|
|
GET //?q=select+*+from+users HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---7ILerWwr---D--
|
|
|
|
---7ILerWwr---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---7ILerWwr---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 06:55:19 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---7ILerWwr---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "//"] [unique_id "175005691988.041943"] [ref "o0,18o0,13o13,5v44,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Rx' with parameter `(?i)(union(.*?)select|select.+from)' against variable `ARGS:q' (Value: `select * from users' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "10"] [id "10003"] [rev ""] [msg "SQLi pattern blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "//"] [unique_id "175005691988.041943"] [ref "o0,13o0,13v9,19"]
|
|
|
|
---7ILerWwr---I--
|
|
|
|
---7ILerWwr---J--
|
|
|
|
---7ILerWwr---Z--
|
|
|
|
---NbD6c6Q6---A--
|
|
[16/Jun/2025:06:55:19 +0000] 175005691960.866057 103.250.147.78 60856 172.19.0.2 443
|
|
---NbD6c6Q6---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443//?q=select+*+from+users
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---NbD6c6Q6---D--
|
|
|
|
---NbD6c6Q6---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---NbD6c6Q6---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 06:55:19 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---NbD6c6Q6---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005691960.866057"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---NbD6c6Q6---I--
|
|
|
|
---NbD6c6Q6---J--
|
|
|
|
---NbD6c6Q6---Z--
|
|
|
|
---7ILerWwr---A--
|
|
[16/Jun/2025:06:55:23 +0000] 175005692350.965818 103.250.147.78 60857 172.19.0.2 443
|
|
---7ILerWwr---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---7ILerWwr---D--
|
|
|
|
---7ILerWwr---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---7ILerWwr---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fb233-267"
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 06:55:23 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---7ILerWwr---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005692350.965818"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---7ILerWwr---I--
|
|
|
|
---7ILerWwr---J--
|
|
|
|
---7ILerWwr---Z--
|
|
|
|
---NbD6c6Q6---A--
|
|
[16/Jun/2025:06:55:23 +0000] 17500569233.611857 103.250.147.78 60857 172.19.0.2 443
|
|
---NbD6c6Q6---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---NbD6c6Q6---D--
|
|
|
|
---NbD6c6Q6---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---NbD6c6Q6---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 06:55:23 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---NbD6c6Q6---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "17500569233.611857"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---NbD6c6Q6---I--
|
|
|
|
---NbD6c6Q6---J--
|
|
|
|
---NbD6c6Q6---Z--
|
|
|
|
---7ILerWwr---A--
|
|
[16/Jun/2025:07:05:30 +0000] 175005753018.981812 195.184.76.235 53569 172.19.0.2 443
|
|
---7ILerWwr---B--
|
|
GET / HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Connection: close
|
|
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Accept-Language: en-US,en;q=0.5
|
|
|
|
---7ILerWwr---D--
|
|
|
|
---7ILerWwr---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---7ILerWwr---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fb233-267"
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: close
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 07:05:30 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---7ILerWwr---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005753018.981812"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---7ILerWwr---I--
|
|
|
|
---7ILerWwr---J--
|
|
|
|
---7ILerWwr---Z--
|
|
|
|
---NbD6c6Q6---A--
|
|
[16/Jun/2025:07:05:32 +0000] 175005753282.159031 54.242.155.61 13138 172.19.0.2 443
|
|
---NbD6c6Q6---B--
|
|
GET / HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
|
|
Accept: */*
|
|
Accept-Encoding: gzip
|
|
|
|
---NbD6c6Q6---D--
|
|
|
|
---NbD6c6Q6---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---NbD6c6Q6---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fb233-267"
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 07:05:32 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---NbD6c6Q6---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005753282.159031"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---NbD6c6Q6---I--
|
|
|
|
---NbD6c6Q6---J--
|
|
|
|
---NbD6c6Q6---Z--
|
|
|
|
---mVTXJ4su---A--
|
|
[16/Jun/2025:07:06:27 +0000] 175005758725.484606 103.250.147.78 60897 172.19.0.2 443
|
|
---mVTXJ4su---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fb233-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 05:57:07 GMT
|
|
Priority: u=0, i
|
|
|
|
---mVTXJ4su---D--
|
|
|
|
---mVTXJ4su---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 07:06:27 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
ETag: "684fb233-267"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---mVTXJ4su---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005758725.484606"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---mVTXJ4su---I--
|
|
|
|
---mVTXJ4su---J--
|
|
|
|
---mVTXJ4su---Z--
|
|
|
|
---mVTXJ4su---A--
|
|
[16/Jun/2025:07:08:00 +0000] 175005768064.581437 103.250.147.78 60905 172.19.0.2 443
|
|
---mVTXJ4su---B--
|
|
GET /? HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---mVTXJ4su---D--
|
|
|
|
---mVTXJ4su---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---mVTXJ4su---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fb233-267"
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 07:08:00 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---mVTXJ4su---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005768064.581437"] [ref "o0,18o0,13o13,5v22,18"]
|
|
|
|
---mVTXJ4su---I--
|
|
|
|
---mVTXJ4su---J--
|
|
|
|
---mVTXJ4su---Z--
|
|
|
|
---oLSvWVQJ---A--
|
|
[16/Jun/2025:07:08:36 +0000] 175005771696.400463 103.250.147.78 60905 172.19.0.2 443
|
|
---oLSvWVQJ---B--
|
|
GET /?q=select+*+from+users HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---oLSvWVQJ---D--
|
|
|
|
---oLSvWVQJ---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---oLSvWVQJ---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 07:08:36 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---oLSvWVQJ---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005771696.400463"] [ref "o0,18o0,13o13,5v43,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Rx' with parameter `(?i)(union(.*?)select|select.+from)' against variable `ARGS:q' (Value: `select * from users' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "10"] [id "10003"] [rev ""] [msg "SQLi pattern blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005771696.400463"] [ref "o0,13o0,13v8,19"]
|
|
|
|
---oLSvWVQJ---I--
|
|
|
|
---oLSvWVQJ---J--
|
|
|
|
---oLSvWVQJ---Z--
|
|
|
|
---mVTXJ4su---A--
|
|
[16/Jun/2025:07:19:16 +0000] 175005835698.734447 195.184.76.110 50065 172.19.0.2 443
|
|
---mVTXJ4su---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Connection: close
|
|
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Accept-Language: en-US,en;q=0.5
|
|
|
|
---mVTXJ4su---D--
|
|
|
|
---mVTXJ4su---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---mVTXJ4su---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 07:19:16 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: close
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---mVTXJ4su---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005835698.734447"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---mVTXJ4su---I--
|
|
|
|
---mVTXJ4su---J--
|
|
|
|
---mVTXJ4su---Z--
|
|
|
|
---mVTXJ4su---A--
|
|
[16/Jun/2025:07:38:23 +0000] 175005950363.966255 103.250.147.78 61052 172.19.0.2 443
|
|
---mVTXJ4su---B--
|
|
GET /?q=select+*+from+users HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---mVTXJ4su---D--
|
|
|
|
---mVTXJ4su---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---mVTXJ4su---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 07:38:23 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---mVTXJ4su---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005950363.966255"] [ref "o0,18o0,13o13,5v43,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Rx' with parameter `(?i)(union(.*?)select|select.+from)' against variable `ARGS:q' (Value: `select * from users' ) [file "/usr/local/nginx/conf/modsec/custom-rules.conf"] [line "10"] [id "10003"] [rev ""] [msg "SQLi pattern blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.2"] [uri "/"] [unique_id "175005950363.966255"] [ref "o0,13o0,13v8,19"]
|
|
|
|
---mVTXJ4su---I--
|
|
|
|
---mVTXJ4su---J--
|
|
|
|
---mVTXJ4su---Z--
|
|
|
|
---oLSvWVQJ---A--
|
|
[16/Jun/2025:07:38:23 +0000] 175005950336.171960 103.250.147.78 61052 172.19.0.2 443
|
|
---oLSvWVQJ---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/?q=select+*+from+users
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---oLSvWVQJ---D--
|
|
|
|
---oLSvWVQJ---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---oLSvWVQJ---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 07:38:23 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---oLSvWVQJ---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.2"] [uri "/favicon.ico"] [unique_id "175005950336.171960"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---oLSvWVQJ---I--
|
|
|
|
---oLSvWVQJ---J--
|
|
|
|
---oLSvWVQJ---Z--
|
|
|
|
---k66rYemC---A--
|
|
[16/Jun/2025:08:13:30 +0000] 175006161076.395399 103.250.147.78 61243 172.19.0.3 443
|
|
---k66rYemC---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fb233-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 05:57:07 GMT
|
|
Priority: u=0, i
|
|
|
|
---k66rYemC---D--
|
|
|
|
---k66rYemC---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:13:30 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 05:57:07 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
ETag: "684fb233-267"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---k66rYemC---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006161076.395399"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---k66rYemC---I--
|
|
|
|
---k66rYemC---J--
|
|
|
|
---k66rYemC---Z--
|
|
|
|
---QXk20x69---A--
|
|
[16/Jun/2025:08:16:31 +0000] 17500617910.704362 103.250.147.78 61255 172.19.0.3 443
|
|
---QXk20x69---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---QXk20x69---D--
|
|
|
|
---QXk20x69---E--
|
|
Hello from Node app!
|
|
|
|
---QXk20x69---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
X-Powered-By: Express
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html; charset=utf-8
|
|
Content-Length: 20
|
|
Date: Mon, 16 Jun 2025 08:16:31 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---QXk20x69---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "17500617910.704362"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---QXk20x69---I--
|
|
|
|
---QXk20x69---J--
|
|
|
|
---QXk20x69---Z--
|
|
|
|
---fUYsnVzE---A--
|
|
[16/Jun/2025:08:16:31 +0000] 175006179119.060509 103.250.147.78 61255 172.19.0.3 443
|
|
---fUYsnVzE---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---fUYsnVzE---D--
|
|
|
|
---fUYsnVzE---F--
|
|
HTTP/1.1 200
|
|
|
|
---fUYsnVzE---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/favicon.ico"] [unique_id "175006179119.060509"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---fUYsnVzE---I--
|
|
|
|
---fUYsnVzE---J--
|
|
|
|
---fUYsnVzE---Z--
|
|
|
|
---QXk20x69---A--
|
|
[16/Jun/2025:08:16:33 +0000] 175006179335.751150 103.250.147.78 61256 172.19.0.3 443
|
|
---QXk20x69---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---QXk20x69---D--
|
|
|
|
---QXk20x69---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:16:33 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Powered-By: Express
|
|
ETag: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---QXk20x69---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006179335.751150"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---QXk20x69---I--
|
|
|
|
---QXk20x69---J--
|
|
|
|
---QXk20x69---Z--
|
|
|
|
---fUYsnVzE---A--
|
|
[16/Jun/2025:08:16:46 +0000] 175006180685.730669 103.250.147.78 61256 172.19.0.3 443
|
|
---fUYsnVzE---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---fUYsnVzE---D--
|
|
|
|
---fUYsnVzE---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---fUYsnVzE---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:16:46 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---fUYsnVzE---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006180685.730669"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006180685.730669"] [ref "o0,4v16,4"]
|
|
|
|
---fUYsnVzE---I--
|
|
|
|
---fUYsnVzE---J--
|
|
|
|
---fUYsnVzE---Z--
|
|
|
|
---XF97TaRT---A--
|
|
[16/Jun/2025:08:16:48 +0000] 175006180836.554790 103.250.147.78 61256 172.19.0.3 443
|
|
---XF97TaRT---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---XF97TaRT---D--
|
|
|
|
---XF97TaRT---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---XF97TaRT---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:16:48 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---XF97TaRT---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006180836.554790"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006180836.554790"] [ref "o0,4v16,4"]
|
|
|
|
---XF97TaRT---I--
|
|
|
|
---XF97TaRT---J--
|
|
|
|
---XF97TaRT---Z--
|
|
|
|
---jPAO39jZ---A--
|
|
[16/Jun/2025:08:16:48 +0000] 175006180832.792278 103.250.147.78 61256 172.19.0.3 443
|
|
---jPAO39jZ---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/?testparam=test
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---jPAO39jZ---D--
|
|
|
|
---jPAO39jZ---F--
|
|
HTTP/1.1 200
|
|
|
|
---jPAO39jZ---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/favicon.ico"] [unique_id "175006180832.792278"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---jPAO39jZ---I--
|
|
|
|
---jPAO39jZ---J--
|
|
|
|
---jPAO39jZ---Z--
|
|
|
|
---QXk20x69---A--
|
|
[16/Jun/2025:08:18:24 +0000] 17500619045.336015 103.250.147.78 61263 172.19.0.3 443
|
|
---QXk20x69---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---QXk20x69---D--
|
|
|
|
---QXk20x69---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:18:24 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Powered-By: Express
|
|
ETag: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---QXk20x69---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "17500619045.336015"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---QXk20x69---I--
|
|
|
|
---QXk20x69---J--
|
|
|
|
---QXk20x69---Z--
|
|
|
|
---fUYsnVzE---A--
|
|
[16/Jun/2025:08:18:54 +0000] 175006193482.248188 103.250.147.78 61263 172.19.0.3 443
|
|
---fUYsnVzE---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---fUYsnVzE---D--
|
|
|
|
---fUYsnVzE---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---fUYsnVzE---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 08:18:54 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---fUYsnVzE---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006193482.248188"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.19.0.3"] [uri "/"] [unique_id "175006193482.248188"] [ref "o0,4v16,4"]
|
|
|
|
---fUYsnVzE---I--
|
|
|
|
---fUYsnVzE---J--
|
|
|
|
---fUYsnVzE---Z--
|
|
|
|
---AKjDQbPC---A--
|
|
[16/Jun/2025:09:20:40 +0000] 175006564052.605740 103.250.147.78 61563 172.18.0.3 443
|
|
---AKjDQbPC---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---AKjDQbPC---D--
|
|
|
|
---AKjDQbPC---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---AKjDQbPC---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:20:40 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---AKjDQbPC---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/"] [unique_id "175006564052.605740"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.18.0.3"] [uri "/"] [unique_id "175006564052.605740"] [ref "o0,4v16,4"]
|
|
|
|
---AKjDQbPC---I--
|
|
|
|
---AKjDQbPC---J--
|
|
|
|
---AKjDQbPC---Z--
|
|
|
|
---RXCEiyo6---A--
|
|
[16/Jun/2025:09:20:40 +0000] 175006564032.405538 103.250.147.78 61563 172.18.0.3 443
|
|
---RXCEiyo6---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/?testparam=test
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---RXCEiyo6---D--
|
|
|
|
---RXCEiyo6---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---RXCEiyo6---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:20:40 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---RXCEiyo6---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/favicon.ico"] [unique_id "175006564032.405538"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---RXCEiyo6---I--
|
|
|
|
---RXCEiyo6---J--
|
|
|
|
---RXCEiyo6---Z--
|
|
|
|
---AKjDQbPC---A--
|
|
[16/Jun/2025:09:20:43 +0000] 175006564373.676724 103.250.147.78 61564 172.18.0.3 443
|
|
---AKjDQbPC---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---AKjDQbPC---D--
|
|
|
|
---AKjDQbPC---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---AKjDQbPC---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe187-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:19:03 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 09:20:43 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---AKjDQbPC---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/"] [unique_id "175006564373.676724"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---AKjDQbPC---I--
|
|
|
|
---AKjDQbPC---J--
|
|
|
|
---AKjDQbPC---Z--
|
|
|
|
---5x2Yyt1q---A--
|
|
[16/Jun/2025:09:32:05 +0000] 175006632526.029717 103.250.147.78 61607 172.18.0.2 443
|
|
---5x2Yyt1q---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fe187-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 09:19:03 GMT
|
|
Priority: u=0, i
|
|
|
|
---5x2Yyt1q---D--
|
|
|
|
---5x2Yyt1q---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---5x2Yyt1q---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe47f-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:31:43 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 09:32:05 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---5x2Yyt1q---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006632526.029717"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---5x2Yyt1q---I--
|
|
|
|
---5x2Yyt1q---J--
|
|
|
|
---5x2Yyt1q---Z--
|
|
|
|
---V05faCtQ---A--
|
|
[16/Jun/2025:09:32:18 +0000] 175006633890.249503 103.250.147.78 61607 172.18.0.2 443
|
|
---V05faCtQ---B--
|
|
GET /?testpatame=ueu HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---V05faCtQ---D--
|
|
|
|
---V05faCtQ---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---V05faCtQ---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe47f-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:31:43 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 09:32:18 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---V05faCtQ---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006633890.249503"] [ref "o0,18o0,13o13,5v36,18"]
|
|
|
|
---V05faCtQ---I--
|
|
|
|
---V05faCtQ---J--
|
|
|
|
---V05faCtQ---Z--
|
|
|
|
---934L8GZM---A--
|
|
[16/Jun/2025:09:32:22 +0000] 175006634238.801111 103.250.147.78 61607 172.18.0.2 443
|
|
---934L8GZM---B--
|
|
GET /?testpatame=ueu HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fe47f-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 09:31:43 GMT
|
|
Priority: u=0, i
|
|
|
|
---934L8GZM---D--
|
|
|
|
---934L8GZM---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:32:22 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 09:31:43 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
ETag: "684fe47f-267"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---934L8GZM---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006634238.801111"] [ref "o0,18o0,13o13,5v36,18"]
|
|
|
|
---934L8GZM---I--
|
|
|
|
---934L8GZM---J--
|
|
|
|
---934L8GZM---Z--
|
|
|
|
---5x2Yyt1q---A--
|
|
[16/Jun/2025:09:33:45 +0000] 175006642599.080701 103.250.147.78 61614 172.18.0.2 443
|
|
---5x2Yyt1q---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---5x2Yyt1q---D--
|
|
|
|
---5x2Yyt1q---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---5x2Yyt1q---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:33:45 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---5x2Yyt1q---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006642599.080701"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006642599.080701"] [ref "o0,4v16,4"]
|
|
|
|
---5x2Yyt1q---I--
|
|
|
|
---5x2Yyt1q---J--
|
|
|
|
---5x2Yyt1q---Z--
|
|
|
|
---V05faCtQ---A--
|
|
[16/Jun/2025:09:33:45 +0000] 175006642562.751932 103.250.147.78 61614 172.18.0.2 443
|
|
---V05faCtQ---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/?testparam=test
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---V05faCtQ---D--
|
|
|
|
---V05faCtQ---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---V05faCtQ---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:33:45 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---V05faCtQ---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/favicon.ico"] [unique_id "175006642562.751932"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---V05faCtQ---I--
|
|
|
|
---V05faCtQ---J--
|
|
|
|
---V05faCtQ---Z--
|
|
|
|
---5x2Yyt1q---A--
|
|
[16/Jun/2025:09:33:46 +0000] 175006642621.993886 103.250.147.78 61615 172.18.0.2 443
|
|
---5x2Yyt1q---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---5x2Yyt1q---D--
|
|
|
|
---5x2Yyt1q---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---5x2Yyt1q---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 09:33:46 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---5x2Yyt1q---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006642621.993886"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006642621.993886"] [ref "o0,4v16,4"]
|
|
|
|
---5x2Yyt1q---I--
|
|
|
|
---5x2Yyt1q---J--
|
|
|
|
---5x2Yyt1q---Z--
|
|
|
|
---bLbQ0wQW---A--
|
|
[16/Jun/2025:10:01:24 +0000] 175006808472.334869 103.250.147.78 61803 172.18.0.2 443
|
|
---bLbQ0wQW---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---bLbQ0wQW---D--
|
|
|
|
---bLbQ0wQW---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---bLbQ0wQW---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 10:01:24 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---bLbQ0wQW---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006808472.334869"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006808472.334869"] [ref "o0,4v16,4"]
|
|
|
|
---bLbQ0wQW---I--
|
|
|
|
---bLbQ0wQW---J--
|
|
|
|
---bLbQ0wQW---Z--
|
|
|
|
---XX1IPPwE---A--
|
|
[16/Jun/2025:10:01:24 +0000] 17500680847.096073 103.250.147.78 61803 172.18.0.2 443
|
|
---XX1IPPwE---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
Sec-Fetch-Dest: image
|
|
Sec-Fetch-Mode: no-cors
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Priority: u=6
|
|
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Referer: https://13.234.29.148:8443/?testparam=test
|
|
Connection: keep-alive
|
|
Sec-Fetch-Site: same-origin
|
|
|
|
---XX1IPPwE---D--
|
|
|
|
---XX1IPPwE---E--
|
|
<html>\x0d\x0a<head><title>404 Not Found</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>404 Not Found</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---XX1IPPwE---F--
|
|
HTTP/1.1 404
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 10:01:24 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---XX1IPPwE---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/favicon.ico"] [unique_id "17500680847.096073"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---XX1IPPwE---I--
|
|
|
|
---XX1IPPwE---J--
|
|
|
|
---XX1IPPwE---Z--
|
|
|
|
---bLbQ0wQW---A--
|
|
[16/Jun/2025:10:01:27 +0000] 175006808768.284849 103.250.147.78 61806 172.18.0.2 443
|
|
---bLbQ0wQW---B--
|
|
GET /?testparam=test HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---bLbQ0wQW---D--
|
|
|
|
---bLbQ0wQW---E--
|
|
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a
|
|
|
|
---bLbQ0wQW---F--
|
|
HTTP/1.1 403
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 10:01:27 GMT
|
|
Content-Length: 146
|
|
Content-Type: text/html
|
|
X-Content-Type-Options: nosniff
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---bLbQ0wQW---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006808768.284849"] [ref "o0,18o0,13o13,5v36,18"]
|
|
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Contains' with parameter `test' against variable `ARGS:testparam' (Value: `test' ) [file "/usr/local/nginx/conf/modsec/modsecurity.conf"] [line "9"] [id "12345"] [rev ""] [msg "Test param blocked"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006808768.284849"] [ref "o0,4v16,4"]
|
|
|
|
---bLbQ0wQW---I--
|
|
|
|
---bLbQ0wQW---J--
|
|
|
|
---bLbQ0wQW---Z--
|
|
|
|
---XX1IPPwE---A--
|
|
[16/Jun/2025:10:01:29 +0000] 17500680892.173512 103.250.147.78 61806 172.18.0.2 443
|
|
---XX1IPPwE---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fe47f-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 09:31:43 GMT
|
|
Priority: u=0, i
|
|
|
|
---XX1IPPwE---D--
|
|
|
|
---XX1IPPwE---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---XX1IPPwE---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe6fd-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:42:21 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 10:01:29 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---XX1IPPwE---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "17500680892.173512"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---XX1IPPwE---I--
|
|
|
|
---XX1IPPwE---J--
|
|
|
|
---XX1IPPwE---Z--
|
|
|
|
---soPrO2hG---A--
|
|
[16/Jun/2025:10:01:32 +0000] 175006809250.776575 103.250.147.78 61806 172.18.0.2 443
|
|
---soPrO2hG---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fe6fd-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 09:42:21 GMT
|
|
Priority: u=0, i
|
|
|
|
---soPrO2hG---D--
|
|
|
|
---soPrO2hG---F--
|
|
HTTP/1.1 304
|
|
Server: nginx
|
|
Date: Mon, 16 Jun 2025 10:01:32 GMT
|
|
Last-Modified: Mon, 16 Jun 2025 09:42:21 GMT
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
ETag: "684fe6fd-267"
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
X-Content-Type-Options: nosniff
|
|
X-Frame-Options: SAMEORIGIN
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
|
|
---soPrO2hG---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006809250.776575"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---soPrO2hG---I--
|
|
|
|
---soPrO2hG---J--
|
|
|
|
---soPrO2hG---Z--
|
|
|
|
---bLbQ0wQW---A--
|
|
[16/Jun/2025:10:02:22 +0000] 175006814273.728575 64.62.197.76 19773 172.18.0.2 443
|
|
---bLbQ0wQW---B--
|
|
GET / HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
|
|
Accept: */*
|
|
Accept-Encoding: gzip
|
|
|
|
---bLbQ0wQW---D--
|
|
|
|
---bLbQ0wQW---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---bLbQ0wQW---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe6fd-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:42:21 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 10:02:22 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---bLbQ0wQW---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006814273.728575"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---bLbQ0wQW---I--
|
|
|
|
---bLbQ0wQW---J--
|
|
|
|
---bLbQ0wQW---Z--
|
|
|
|
---eXpssPo1---A--
|
|
[16/Jun/2025:10:03:34 +0000] 175006821419.624479 64.62.197.74 35427 172.18.0.3 443
|
|
---eXpssPo1---B--
|
|
GET /webui/ HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0
|
|
Accept: */*
|
|
Accept-Encoding: gzip
|
|
|
|
---eXpssPo1---D--
|
|
|
|
---eXpssPo1---E--
|
|
<!DOCTYPE html>\x0a<html lang="en">\x0a<head>\x0a<meta charset="utf-8">\x0a<title>Error</title>\x0a</head>\x0a<body>\x0a<pre>Cannot GET /webui/</pre>\x0a</body>\x0a</html>\x0a
|
|
|
|
---eXpssPo1---F--
|
|
HTTP/1.1 404
|
|
X-Frame-Options: SAMEORIGIN
|
|
Content-Security-Policy: default-src 'none'
|
|
X-Powered-By: Express
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Content-Type-Options: nosniff
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html; charset=utf-8
|
|
Content-Length: 145
|
|
Date: Mon, 16 Jun 2025 10:03:34 GMT
|
|
Server: nginx
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---eXpssPo1---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/webui/"] [unique_id "175006821419.624479"] [ref "o0,18o0,13o13,5v27,18"]
|
|
|
|
---eXpssPo1---I--
|
|
|
|
---eXpssPo1---J--
|
|
|
|
---eXpssPo1---Z--
|
|
|
|
---eXpssPo1---A--
|
|
[16/Jun/2025:10:03:37 +0000] 17500682176.927329 103.250.147.78 61819 172.18.0.3 443
|
|
---eXpssPo1---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: "684fe6fd-267"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
If-Modified-Since: Mon, 16 Jun 2025 09:42:21 GMT
|
|
Priority: u=0, i
|
|
|
|
---eXpssPo1---D--
|
|
|
|
---eXpssPo1---E--
|
|
Hello from Node app!
|
|
|
|
---eXpssPo1---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
X-Powered-By: Express
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html; charset=utf-8
|
|
Content-Length: 20
|
|
Date: Mon, 16 Jun 2025 10:03:37 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---eXpssPo1---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/"] [unique_id "17500682176.927329"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---eXpssPo1---I--
|
|
|
|
---eXpssPo1---J--
|
|
|
|
---eXpssPo1---Z--
|
|
|
|
---eXpssPo1---A--
|
|
[16/Jun/2025:10:04:29 +0000] 175006826953.087700 64.62.197.74 11339 172.18.0.3 443
|
|
---eXpssPo1---B--
|
|
GET /favicon.ico HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
|
|
Accept: */*
|
|
Accept-Encoding: gzip
|
|
|
|
---eXpssPo1---D--
|
|
|
|
---eXpssPo1---E--
|
|
<!DOCTYPE html>\x0a<html lang="en">\x0a<head>\x0a<meta charset="utf-8">\x0a<title>Error</title>\x0a</head>\x0a<body>\x0a<pre>Cannot GET /favicon.ico</pre>\x0a</body>\x0a</html>\x0a
|
|
|
|
---eXpssPo1---F--
|
|
HTTP/1.1 404
|
|
X-Frame-Options: SAMEORIGIN
|
|
Content-Security-Policy: default-src 'none'
|
|
X-Powered-By: Express
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Content-Type-Options: nosniff
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html; charset=utf-8
|
|
Content-Length: 150
|
|
Date: Mon, 16 Jun 2025 10:04:29 GMT
|
|
Server: nginx
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---eXpssPo1---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/favicon.ico"] [unique_id "175006826953.087700"] [ref "o0,18o0,13o13,5v32,18"]
|
|
|
|
---eXpssPo1---I--
|
|
|
|
---eXpssPo1---J--
|
|
|
|
---eXpssPo1---Z--
|
|
|
|
---eXpssPo1---A--
|
|
[16/Jun/2025:10:04:57 +0000] 175006829763.378876 64.62.197.73 21975 172.18.0.3 443
|
|
---eXpssPo1---B--
|
|
GET / HTTP/1.1
|
|
Host: 13.234.29.148:8443
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
|
|
Accept: */*
|
|
Accept-Encoding: gzip
|
|
|
|
---eXpssPo1---D--
|
|
|
|
---eXpssPo1---E--
|
|
Hello from Node app!
|
|
|
|
---eXpssPo1---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
X-Powered-By: Express
|
|
Connection: keep-alive
|
|
X-XSS-Protection: 1; mode=block
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html; charset=utf-8
|
|
Content-Length: 20
|
|
Date: Mon, 16 Jun 2025 10:04:57 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---eXpssPo1---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.3"] [uri "/"] [unique_id "175006829763.378876"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---eXpssPo1---I--
|
|
|
|
---eXpssPo1---J--
|
|
|
|
---eXpssPo1---Z--
|
|
|
|
---f3O8zEa9---A--
|
|
[16/Jun/2025:10:23:51 +0000] 175006943161.070633 103.250.147.78 62084 172.18.0.2 443
|
|
---f3O8zEa9---B--
|
|
GET / HTTP/1.1
|
|
Sec-Fetch-User: ?1
|
|
Sec-Fetch-Site: none
|
|
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:139.0) Gecko/20100101 Firefox/139.0
|
|
Upgrade-Insecure-Requests: 1
|
|
If-None-Match: W/"14-xrFyu1/zI7D6Ig0zrxUGsRvZ+Ng"
|
|
Connection: keep-alive
|
|
Sec-Fetch-Mode: navigate
|
|
Accept-Encoding: gzip, deflate, br, zstd
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
|
|
Sec-Fetch-Dest: document
|
|
Host: 13.234.29.148:8443
|
|
Priority: u=0, i
|
|
|
|
---f3O8zEa9---D--
|
|
|
|
---f3O8zEa9---E--
|
|
<!DOCTYPE html>\x0a<html>\x0a<head>\x0a<title>Welcome to nginx!</title>\x0a<style>\x0ahtml { color-scheme: light dark; }\x0abody { width: 35em; margin: 0 auto;\x0afont-family: Tahoma, Verdana, Arial, sans-serif; }\x0a</style>\x0a</head>\x0a<body>\x0a<h1>Welcome to nginx!</h1>\x0a<p>If you see this page, the nginx web server is successfully installed and\x0aworking. Further configuration is required.</p>\x0a\x0a<p>For online documentation and support please refer to\x0a<a href="http://nginx.org/">nginx.org</a>.<br/>\x0aCommercial support is available at\x0a<a href="http://nginx.com/">nginx.com</a>.</p>\x0a\x0a<p><em>Thank you for using nginx.</em></p>\x0a</body>\x0a</html>\x0a
|
|
|
|
---f3O8zEa9---F--
|
|
HTTP/1.1 200
|
|
Referrer-Policy: strict-origin-when-cross-origin
|
|
X-Frame-Options: SAMEORIGIN
|
|
ETag: "684fe6fd-267"
|
|
Last-Modified: Mon, 16 Jun 2025 09:42:21 GMT
|
|
X-XSS-Protection: 1; mode=block
|
|
Connection: keep-alive
|
|
X-Content-Type-Options: nosniff
|
|
Content-Type: text/html
|
|
Content-Length: 615
|
|
Date: Mon, 16 Jun 2025 10:23:51 GMT
|
|
Server: nginx
|
|
Permissions-Policy: geolocation=(), microphone=()
|
|
|
|
---f3O8zEa9---H--
|
|
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?:^([\d.]+|\[[\da-f:]+\]|[\da-f:]+)(:[\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Value: `13.234.29.148:8443' ) [file "/usr/local/nginx/conf/modsec/crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "712"] [id "920350"] [rev ""] [msg "Host header is a numeric IP address"] [data "13.234.29.148:8443"] [severity "4"] [ver "OWASP_CRS/4.16.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "172.18.0.2"] [uri "/"] [unique_id "175006943161.070633"] [ref "o0,18o0,13o13,5v21,18"]
|
|
|
|
---f3O8zEa9---I--
|
|
|
|
---f3O8zEa9---J--
|
|
|
|
---f3O8zEa9---Z--
|
|
|