Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2019:11:21-08:16:54 sfrf-fw1-1 httpd[6008]: [security2:error] [pid 6008:tid 3799923568] [client :65363] [client ] ModSecurity: Warning. Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/usr/apache/conf/waf/modsecurity_crs_generic_attacks.conf"] [line "163"] [id "950120"] [rev "3"] [msg "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link"] [data "Matched Data: https://mx.xyz.de/owa/ found within TX:1: mx.xyz.de/owa/"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.7"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/WEB_ATTACK/RFI"] [hostname "mx.xyz.de"] [uri "/owa/auth/logon.aspx"] [unique_id "XdY55goZAJEAABd4IEwAAAEh"]
- 2019:11:21-08:16:54 sfrf-fw1-1 httpd: id="0299" srcip="" localip="" size="27137" user="-" host="" method="GET" statuscode="200" reason="-" extra="-" exceptions="SkipURLHardening" time="75902" url="/owa/auth/logon.aspx" server="mx.xyz.de" port="443" query="?url=https%3a%2f%2fmx.xyz.de%2fowa%2f&reason=2" referer="-" cookie="-" set-cookie="-" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" uid="XdY55goZAJEAABd4IEwAAAEh"
- 2019:11:21-08:16:54 sfrf-fw1-1 httpd: id="0299" srcip="" localip="" size="146" user="-" host="" method="POST" statuscode="302" reason="-" extra="-" exceptions="SkipURLHardening" time="9412" url="/owa/auth.owa" server="mx.xyz.de" port="443" query="" referer="-" cookie="PBack=0" set-cookie="cadata=MFXWmvQ5cVANt9p01s9K+PD/bOouvgCVddECfEVZTYmv5gh23qpBV8RDN5R+6ex/ZBB0927Oz97cYDYv1+x9H6Lkg9YUwgMvJAcAWAZfA5EMs7mxkXctwZwcsf8WGumEKgB6oM5/Ow6saNs1rF6x7TjsCbLz/dx/+hqRgFCgmcc71Xcb3iAS+21ZCQ6HrJlN; path=/; secure; HttpOnly, cadataTTL=K3F79lm6n9KmIsrUN9pIQQ==; path=/; secure; HttpOnly, cadataKey=BPo07+GitGHjF2Bt1FMe51/Hk+EbJ1+zasrJlo4mxgiIuImODvwvtXy4AG1zO1XcmVoIpEucSnwSmJgH42XXKlq+l4W4eM3YpoES64ABd0ya+MzoO1vDk0Va7mvKBZ8fXju+KALwafSOiMtEGY1JVoLxP9sx4hxwlW9dhz4Ade5g7vuo6Jmh6Lo8OzqgJtSiQs0T3SnBsgsZHILLsAFdYIeIoWIOW4PM8vKzkEx4ubIQgBvhV1RKvD6RsCU6LFHLtn2WGas+2FWDvIpsWW28M/B72hl/iDMb6ThFsWS1tLPrLUB78dCzCkxJ2FRjFr8w1fri/qsH8+eE18U/MrkDig==; path=/; secure; HttpOnly, cadataIV=pn+ztRWKTsCJMQEoMGB23CSljV6bYomPXjhAzdcP2jF
- 2019:11:21-08:16:54 sfrf-fw1-1 httpd: kk0rS3C1ZTrZWj2ab6txsghcBWl626Syw4flbKSNrz8Ugu2E7Pli232v5SQV0UNcLPpuZUYwbjN+TsPlo3UZcpsybpGNmnFttr9IKccy0Sn2Rl1vX8kzaL7B0TmeKWkF8Dou5vir9jR2sWl2jDBmPghbML8/ifvW2QYo6vGxgA3stHOhBK6ks8qkNPdW5CRtXRcz64qNNdnBTo/vTsrccnkHlCsgHqNaj1/1AwBPK2q3HQ4e6m1NfwdVvNzhMxx0Hapklllwps+9w4v9G8ha82XBxzITay3GtP3btNELu+Q==; path=/; secure; HttpOnly, cadataSig=KCex5Q17Zt5gfE4wVDQ9ZWGOHD+hBVoD3OrVKfeRIdv9eJbKAMwYgWKnoR/WcN0JbjZeaitOY45nUs16RwRHfH/DgyCjB9Rk+xLVr/bfDmoq1Z1ksEslmolzXp+H0m6YGBNFVaXzEAJLT1xL0UWNhjpc8WJhZ4Li/bcHqHpYPkaVehsB4Di7apiAmTYqxICsomoz6LA1FxOloWkWqN2X6ld0T3V1QgDEodo0YIUGeZfLLaoB+1YQ8pN9m8UHlxkaKlVaGePclvbGLW0f9TapfwISZq2gC2pkALvzFJtk4K0Mo0pYaGrTx7MVV1N4pp1Jve2fQVloRyeQJoDep66tOg==; path=/; secure; HttpOnly" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" uid="XdY55goZAJEAABd4IE0AAAEh"
- 2019:11:21-08:16:55 sfrf-fw1-1 httpd: id="0299" srcip="" localip="" size="183" user="-" host="" method="GET" statuscode="302" reason="-" extra="-" exceptions="SkipURLHardening" time="5455" url="/owa/" server="mx.xyz.de" port="443" query="" referer="-" cookie="-" set-cookie="-" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" uid="XdY55woZAJEAABd4IE4AAAEh"
- 2019:11:21-08:16:56 sfrf-fw1-1 httpd[11409]: [security2:error] [pid 11409:tid 3774745456] [client :65364] [client 79.226.76.80] ModSecurity: Warning. Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/usr/apache/conf/waf/modsecurity_crs_generic_attacks.conf"] [line "163"] [id "950120"] [rev "3"] [msg "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link"] [data "Matched Data: https://mx.xyz.de/owa/ found within TX:1: mx.xyz.de/owa/"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.7"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/WEB_ATTACK/RFI"] [hostname "mx.xyz.de"] [uri "/owa/auth/logon.aspx"] [unique_id "XdY56AoZAJEAACyRWCcAAABc"]
- 2019:11:21-08:16:56 sfrf-fw1-1 httpd: id="0299" srcip="" localip="" size="27137" user="-" host="" method="GET" statuscode="200" reason="-" extra="-" exceptions="SkipURLHardening" time="78561" url="/owa/auth/logon.aspx" server="mx.xyz.de" port="443" query="?url=https%3a%2f%2fmx.xyz.de%2fowa%2f&reason=2" referer="-" cookie="-" set-cookie="-" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" uid="XdY56AoZAJEAACyRWCcAAABc"
- 2019:11:21-08:16:56 sfrf-fw1-1 httpd: id="0299" srcip="" localip="" size="146" user="-" host="" method="POST" statuscode="302" reason="-" extra="-" exceptions="SkipURLHardening" time="9451" url="/owa/auth.owa" server="mx.xyz.de" port="443" query="" referer="-" cookie="PBack=0" set-cookie="cadata=YbYqZu6wOtj8MPtlce4entohPHtOj6ehPlY0IeXY0xeNswwdyIot/kXLm3ke8kTiIh1S5hZ/pDYdm8wacOHWYKtTXOOEDIWSIAEPStRTSyGvERS1oP18SXsH+iWyxpLBvGjF4dprwI7tImUG/Ar0hfR92baG3uqp3LxoKfFQYfB+5Mn0Tu8/6ub1CoH8ZmIL; path=/; secure; HttpOnly, cadataTTL=2NhvXzlTuFg1F0SDyV8RoQ==; path=/; secure; HttpOnly, cadataKey=Zd6vcThPFNVSDpI6luXJ4KHIkM1qaihHc5WrafZccHofONs6QVtab/9u0iVrpT34JIlZUfpKvmqsq2uv/GkU/UdzsFOI4hewcPCVRccUYQ0hpyXXGMxXIJQMy6vszEYPypURcdXSzwXfv7EwluIkWXW4Fd/F40kH49dhcEN03QFHVODYEcj4BBokivHI7IDlFPG3Qs5UlHF8HxSKvoMwxJovBojhx+entu1L1K+ZXBVUZvxEm801Jpg4LV5U7bNLmKbs+OEV462Z8H0txwpUBUIAZIMMjOUWgBabfDN03Y+Y8mCQPI9oykclNbZDaetUlqvOH+/XvzB3Asw2OeKZQg==; path=/; secure; HttpOnly, cadataIV=EsyfbGvcV6oeu5vifUuWCOWGIV4OOXESeJIXleNxh2l
- 2019:11:21-08:16:56 sfrf-fw1-1 httpd: 2/xqfURWyIWLElMH3c2jhytr8j1vjV8tGES84mawAu0EXur2AIUb/L7CEYq0mw9xdm7Y6mTDtjSzqZ712+67QatMGfQrHXhD9ptguDJ7wLiyFLy/csSsFH3NJ8KZyiZMlX7Wfn5GDMgx+ha0jrLzbMb5XnCYcxMURRBQ++rgf5tG3NQJmEDW9gU68QXr4o1O4uoewrUoPZVH0hpCCYFZE0hN10fBNy8bRZdD6SKWH5qCzpZ5klJ+7cwSSvj7PJ333bQFRSLpiKCsGx2eYf2GY7nnUtcARr2novjMZGa0img==; path=/; secure; HttpOnly, cadataSig=K/vtuiTTWjaujFy7q3Wu0vC3aKOIZYrUSPmoblR4SG+MbnMZaoLpnPLg6lsnHNUYGHEwlOXqJfp5lQqfkHI9yxyEJNLx/nOTaid0qY+1WbHkVXVp444oy0g8NgKuaefwkINyQsrMwPo0zjFfPkbwWFzYkEVXo5R1Jm0p9px1yHFBprr/bVdPDWFTJBpJLO+Y+R2YGDCOUYK9Eq4XbgfaAx9s9qwiHoBsuIq/vclqsD7cl/gkUorSMV46h8XuYEYv3FMn09/NQjJzm3YtQuuNpU2JluF4tL/xCu3q5rO+WpsuCPdfyfiJuy3F6ngjk1xyDOhXfgv6Cw5tm8SSoTdX0Q==; path=/; secure; HttpOnly" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" uid="XdY56AoZAJEAACyRWCgAAABc"
Advertisement
Add Comment
Please, Sign In to add comment